Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

Windows 7 will not reboot. Please help! [Solved]


  • This topic is locked This topic is locked

#16
CompCav

CompCav

    Member 5k

  • Expert
  • 12,449 posts

Do I just make one to the company and earmark it for you?

You can make it to the site, no earmark required.

Now back to the scans please do the following:







Step 1.

Please download Malwarebytes' Anti-Malware

Double Click mbam-setup.exe to install the application. Please do not accept the trial right now. We just want to run it on demand.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish, so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.


Extra Note:
If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.



Step 2.

Run ESET Online Scan

Note: You can use either Internet Explorer or Mozilla FireFox for this scan.

Vista / 7 users: You will need to to right-click on the either the IE or FF icon in the Start Menu or Quick Launch Bar on the Taskbar and select Run as Administrator from the context menu.

Please go here then click on: Posted Image

If using Mozilla Firefox you will need to download esetsmartinstaller_enu.exe when prompted then double click on it to install.
All of the following instructions work with either Internet Explorer or Mozilla FireFox.

  • Select the option YES, I accept the Terms of Use then click on: Posted Image
  • When prompted allow Add-On/Active X to install.
  • Make sure that the option Scan archives is checked.
  • Now click on Advanced Settings and select the following:
    • Scan for potentially unwanted applications
    • Scan for potentially unsafe applications
    • Enable Anti-Stealth Technology
  • Now click on: Posted Image
  • The virus signature database will begin to download. Be patient this make take some time depending on the speed of your Internet Connection.
  • When completed the Online Scan will begin automatically. The scan may take several hours.
  • Do not touch either the Mouse or keyboard during the scan otherwise it may stall.
  • When completed select Uninstall application on close, make sure you copy the logfile first!
  • Now click on: Posted Image
  • Use notepad to open the logfile located at C:\Program Files\ESET\EsetOnlineScanner\log.txt.
  • Copy and paste that log as a reply to this topic.


Step 3.

Security Check
Download Security Check by screen317 from here or here.

Save it to your Desktop.
Double click SecurityCheck.exe and follow the onscreen instructions inside of the black box.
A Notepad document should open automatically called checkup.txt; please post the contents of that document.


Step 4.

Please post:


mbam log
eset log
security check log


Please give me an update on how your computer is doing!




If you cannot complete the MalwareBytes' scan then please do the following steps also if you are still having BSOD's after running all of this please do the following:


I would download this and have it ready and next time it crashes I would run it take OUT all but one stick of ram and run MEMTEST on one full cycle of 8 TESTS.
I would then replace that ONE stick with the other(s), so you still only have one stick in and run it again. ORhttp://www.geekstogo.com/forum/topic/246994-guide-to-using-memtest86/ you could run it now, but I do not really think it is a ram issue, it is just to eliminate it.
http://www.geekstogo...sing-memtest86/
The guide is comprehensive with images.

Also here is a link to the test you can make on a USB flash drive if you cannot make the CD:

Memtest USB

Let me know the results, if you find any errors the stick(s) of memory is(are) bad. Leave the bad ones out and boot up in normal mode to see if your errors are corrected.

I will respond around 3:00 pm CST next since I am off computer until then.

Regards,

CompCav
  • 0

Advertisements


#17
mikison

mikison

    Member

  • Topic Starter
  • Member
  • PipPip
  • 88 posts
I was able to run all the new scans and below are the logs for MBAM, ESET, and Security Check. Is it okay to update AVG now and proceed normally?
Miki

Malwarebytes Anti-Malware 1.65.1.1000
www.malwarebytes.org

Database version: v2012.11.26.07

Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 9.0.8112.16421
Owner :: MIKI-PC [administrator]

11/26/2012 11:08:44 AM
mbam-log-2012-11-26 (11-08-44).txt

Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 252670
Time elapsed: 8 minute(s), 54 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 1
C:\Windows\svchost.exe (Trojan.Agent) -> Quarantined and deleted successfully.

(end)

[email protected] as CAB hook log:
OnlineScanner64.ocx - registred OK
OnlineScanner.ocx - registred OK
# version=7
# IEXPLORE.EXE=9.00.8112.16421 (WIN7_IE9_RTM.110308-0330)
# OnlineScanner.ocx=1.0.0.6583
# api_version=3.0.2
# EOSSerial=5ab3c1e613b98542a7a21fd4f228fca3
# end=finished
# remove_checked=true
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=true
# antistealth_checked=true
# utc_time=2012-11-26 09:11:56
# local_time=2012-11-26 04:11:56 (-0500, Eastern Standard Time)
# country="United States"
# lang=1033
# osver=6.1.7601 NT Service Pack 1
# compatibility_mode=1024 16777215 100 0 0 0 0 0
# compatibility_mode=5893 16776574 100 94 37227334 105491736 0 0
# compatibility_mode=8192 67108863 100 0 0 0 0 0
# scanned=575754
# found=17
# cleaned=17
# scan_time=16029
C:\Program Files (x86)\Uninstall Information\ib_uninst_342\uninstall.exe a variant of Win32/InstallBrain.H application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Program Files (x86)\Uninstall Information\ib_uninst_343\uninstall.exe a variant of Win32/InstallBrain.H application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Program Files (x86)\Uninstall Information\ib_uninst_383\uninstall.exe a variant of Win32/InstallBrain.H application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Program Files (x86)\Uninstall Information\ib_uninst_514\uninstall.exe a variant of Win32/InstallBrain.H application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\Program Files (x86)\Uninstall Information\ib_uninst_569\uninstall.exe a variant of Win32/InstallBrain.H application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\TDSSKiller_Quarantine\26.11.2012_01.07.14\mbr0000\tdlfs0000\tsk0000.dta a variant of Win32/Olmarik.AYI trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\TDSSKiller_Quarantine\26.11.2012_01.07.14\mbr0000\tdlfs0000\tsk0001.dta a variant of Win64/Olmarik.AM trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\TDSSKiller_Quarantine\26.11.2012_01.07.14\mbr0000\tdlfs0000\tsk0002.dta a variant of Win32/Rootkit.Kryptik.QM trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\TDSSKiller_Quarantine\26.11.2012_01.07.14\mbr0000\tdlfs0000\tsk0003.dta Win64/Olmarik.AN trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\TDSSKiller_Quarantine\26.11.2012_01.07.14\mbr0000\tdlfs0000\tsk0007.dta Win32/Olmarik.AFK trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\TDSSKiller_Quarantine\26.11.2012_01.07.14\mbr0000\tdlfs0000\tsk0008.dta Win64/Olmarik.AK trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\TDSSKiller_Quarantine\26.11.2012_08.15.22\tdlfs0000\tsk0000.dta a variant of Win32/Olmarik.AYI trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\TDSSKiller_Quarantine\26.11.2012_08.15.22\tdlfs0000\tsk0001.dta a variant of Win64/Olmarik.AM trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\TDSSKiller_Quarantine\26.11.2012_08.15.22\tdlfs0000\tsk0002.dta a variant of Win32/Rootkit.Kryptik.QM trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\TDSSKiller_Quarantine\26.11.2012_08.15.22\tdlfs0000\tsk0003.dta Win64/Olmarik.AN trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\TDSSKiller_Quarantine\26.11.2012_08.15.22\tdlfs0000\tsk0007.dta Win32/Olmarik.AFK trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C
C:\TDSSKiller_Quarantine\26.11.2012_08.15.22\tdlfs0000\tsk0008.dta Win64/Olmarik.AK trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C


Results of screen317's Security Check version 0.99.56
Windows 7 Service Pack 1 x64 (UAC is disabled!)
Internet Explorer 9
``````````````Antivirus/Firewall Check:``````````````
Windows Firewall Disabled!
AVG Internet Security 2013
Antivirus up to date!
`````````Anti-malware/Other Utilities Check:`````````
Malwarebytes Anti-Malware version 1.65.1.1000
Java™ 6 Update 21
Java version out of Date!
Adobe Flash Player 11.3.300.265 Flash Player out of Date!
Adobe Reader 9 Adobe Reader out of Date!
Mozilla Firefox (9.0.1)
````````Process Check: objlist.exe by Laurent````````
AVG avgwdsvc.exe
`````````````````System Health check`````````````````
Total Fragmentation on Drive C: 0%
````````````````````End of Log``````````````````````
  • 0

#18
CompCav

CompCav

    Member 5k

  • Expert
  • 12,449 posts

Is it okay to update AVG now and proceed normally?

Yes please update AVG now and make sure it is running properly. Weo do have some security updates to do as well:

Step 1.
  • Open User Accounts by clicking the Start button Posted Image, clicking Control Panel, clicking User Accounts and Family Safety (or clicking User Accounts, if you are connected to a network domain), and then clicking User Accounts.
  • Click Turn User Account Control on.Posted Image Administrator permission required If you are prompted for an administrator password or confirmation, type the password or provide confirmation.


Step 2.

Update Java

Please download JavaRa to your desktop and unzip it to its own folder

Run JavaRa.exe, pick the language of your choice and click Select. Then click Remove Older Versions.
Accept any prompts.
Open JavaRa.exe again and select Search For Updates.
Select Update Using Sun Java's Website then click Search and click on the Open Webpage button. Download and install the latest Java Runtime Environment (JRE) version for your computer.


Step 3.

Update Adobe Reader

Recently there have been vulnerabilities detected in older versions of Adobe Reader. It is strongly suggested that you update to the current version.

Uninstall all previous versions.
Download the latest version from: http://www.adobe.com.../readstep2.html

If you already have Adobe Photoshop® Album Starter Edition installed or do not wish to have it installed UNcheck the box which says Also Download Adobe Photoshop® Album Starter Edition.


Step 4.

Update adobe flash player

We need to uninstall the existing flash player(s). Please go here
Follow steps 1. to 4.
Once flash player is uninstalled go on to the next paragraph.

You will need to download and install both the IE and non-IE versions of Adobe Flashplayer. Make sure to uncheck the install of the McAfee tool before downloading. You will need to select your operating system (Windows 7 64-bit) and then each version to download and install separately.


Once these are installed please give me an update on the issues remaining with your computer.
  • 0

#19
mikison

mikison

    Member

  • Topic Starter
  • Member
  • PipPip
  • 88 posts
I am not sure which Java to download. I don't see Java Runtime Environment--only SE, EE, and ME
  • 0

#20
CompCav

CompCav

    Member 5k

  • Expert
  • 12,449 posts
Download the 64 bit version for windows 7
  • 0

#21
mikison

mikison

    Member

  • Topic Starter
  • Member
  • PipPip
  • 88 posts
In trying to follow steps of removing Flash, when trying to delete the following file, Flash32_11_3_30_271.ocx, I get the following error message:"This action cannot be completed because the file is open in AVG interface."
  • 0

#22
CompCav

CompCav

    Member 5k

  • Expert
  • 12,449 posts
Remove it in safe mode or temporarily disable AVG and then reenable.
  • 0

#23
mikison

mikison

    Member

  • Topic Starter
  • Member
  • PipPip
  • 88 posts
Okay all Flash uninstalled, but now I'm unable to install new Flash player. The download dialog box never initiates. I tried the troubleshooting steps on Adobe site, includding checking the internet settings, and no luck. :(
Miki

Edited by mikison, 26 November 2012 - 06:03 PM.

  • 0

#24
mikison

mikison

    Member

  • Topic Starter
  • Member
  • PipPip
  • 88 posts
I was able to install Flash in safe mode. I rebooted my computer. Running V-E-R-Y slow. IE9 doesn't work well. Had to use Firefox to go to this site. Everything was going really well until I followed the Flash uninstall/install instructions. Outlook still not working and giving me the following error message.
Cannot start Microsoft Outlook. Cannot open the Outlook window. The set of folders cannot be opened. The file
C:\Users/Owner/AppData\Local\Microsoft\Outlook\Outlook1.pst cannot be opened.

Not sure what to do now. Should I recover the old flash player from recycle bin?

Edited by mikison, 26 November 2012 - 06:41 PM.

  • 0

#25
mikison

mikison

    Member

  • Topic Starter
  • Member
  • PipPip
  • 88 posts
FYI I can hear a constant noise in the background as if something is trying to load.
  • 0

Advertisements


#26
CompCav

CompCav

    Member 5k

  • Expert
  • 12,449 posts
Go ahead and uninstall the new flash versions but do not reinstall and let me know the symptoms. We can get fresh copies of flash older versions at file hippo so no worry on getting the old ones.
  • 0

#27
mikison

mikison

    Member

  • Topic Starter
  • Member
  • PipPip
  • 88 posts
Thank you for your help so far. Please let me know if you are gone for the day or what I should do regarding Outlook and IE. Computer running very slow. Took 15 minutes to copy a 3-gb file. :(

I need to know if I need to go buy another computer. I do medical transcription and cannot afford to go much longer without one.
  • 0

#28
CompCav

CompCav

    Member 5k

  • Expert
  • 12,449 posts
Download farbar service scanner to your desktop and then run it.

Posted Image

Tick "All" options.
Press "Scan".
It will create a log (FSS.txt) in the same directory the tool is run.

Please copy and paste the log to your reply
  • 0

#29
mikison

mikison

    Member

  • Topic Starter
  • Member
  • PipPip
  • 88 posts
I am very confused right now as to what to do. What do you want me to install with regard to flash and what to unistall with regards to flash? I can't access the download you just sent me because IE9 is taking 5-10 minutes to load a page. There were so many files uninstalled with flash that I don't know what to do.

Do I mess with flash first or uninstall IE9 or do the farbar service scanner?
  • 0

#30
mikison

mikison

    Member

  • Topic Starter
  • Member
  • PipPip
  • 88 posts
Below is the FSS text file. I am sorry for sounding so frustrated, but I was having no problems following your instructions until today and now I am totally and completely lost.

IE9 doesn't work well. Outlook won't open. Computer has something running constantly in the background and is running at a snail's pace.

Everything was going well until I followed the directions for uninstalling/installing Flash.

Miki

Farbar Service Scanner Version: 09-11-2012
Ran by Owner (administrator) on 26-11-2012 at 21:26:48
Running from "C:\Users\Owner\Desktop"
Windows 7 Home Premium Service Pack 1 (X64)
Boot Mode: Normal
****************************************************************

Internet Services:
============

Connection Status:
==============
Localhost is accessible.
LAN connected.
Google IP is accessible.
Google.com is accessible.
Yahoo IP is accessible.
Yahoo.com is accessible.


Windows Firewall:
=============

Firewall Disabled Policy:
==================
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall"=DWORD:0


System Restore:
============

System Restore Disabled Policy:
========================


Action Center:
============

Windows Update:
============

Windows Autoupdate Disabled Policy:
============================


Windows Defender:
==============
WinDefend Service is not running. Checking service configuration:
The start type of WinDefend service is set to Demand. The default start type is Auto.
The ImagePath of WinDefend service is OK.
The ServiceDll of WinDefend service is OK.


Windows Defender Disabled Policy:
==========================
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Defender]
"DisableAntiSpyware"=DWORD:1


Other Services:
==============


File Check:
========
C:\Windows\System32\nsisvc.dll => MD5 is legit
C:\Windows\System32\drivers\nsiproxy.sys => MD5 is legit
C:\Windows\System32\dhcpcore.dll => MD5 is legit
C:\Windows\System32\drivers\afd.sys => MD5 is legit
C:\Windows\System32\drivers\tdx.sys => MD5 is legit
C:\Windows\System32\Drivers\tcpip.sys
[2012-11-26 02:59] - [2012-10-03 12:56] - 1914248 ____A (Microsoft Corporation) 37608401DFDB388CAF66917F6B2D6FB0

C:\Windows\System32\dnsrslvr.dll => MD5 is legit
C:\Windows\System32\mpssvc.dll => MD5 is legit
C:\Windows\System32\bfe.dll => MD5 is legit
C:\Windows\System32\drivers\mpsdrv.sys => MD5 is legit
C:\Windows\System32\SDRSVC.dll => MD5 is legit
C:\Windows\System32\vssvc.exe => MD5 is legit
C:\Windows\System32\wscsvc.dll => MD5 is legit
C:\Windows\System32\wbem\WMIsvc.dll => MD5 is legit
C:\Windows\System32\wuaueng.dll => MD5 is legit
C:\Windows\System32\qmgr.dll => MD5 is legit
C:\Windows\System32\es.dll => MD5 is legit
C:\Windows\System32\cryptsvc.dll => MD5 is legit
C:\Program Files\Windows Defender\MpSvc.dll => MD5 is legit
C:\Windows\System32\ipnathlp.dll => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit


**** End of log ****
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP