This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

too long to boot - set up screen appears [Solved]

36 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Just for the hell of it, I ran it again.. After the last one, I deleted 16 nasties. After I just ran it immediately, it found 2 more.. where are these coming from???? I do have a question. I opened up Trend Micro and the quarantine is loaded with 1,095 nasties. In the Trojan quarantine there are MANY versions of TROJ_SIREFEF - UV,UT,UP, GF ,FU ,CZJ - good heavens!! Is it OK to delete them from there? Malwarebytes Anti-Malware 1.62.0.1300 www.malwarebytes.org Database version: v2012.07.17.15 Windows 7 Service Pack 1 x64 NTFS Internet Explorer 9.0.8112.16421 DARLENE'S :: DARLENES-PC [administrator] 7/18/2012 4:23:38 PM mbam-log-2012-07-18 (16-46-00).txt Scan type: Quick scan Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM Scan options disabled: P2P Objects scanned: 279683 Time elapsed: 22 minute(s), 9 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 2 HKCR\Interface\{66666666-6666-6666-6666-660066226658} (Adware.GamePlayLab) -> No action taken. HKCR\TypeLib\{44444444-4444-4444-4444-440044224458} (Adware.GamePlayLab) -> No action taken. Registry Values Detected: 0 (No malicious items detected) Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 0 (No malicious items detected) Files Detected: 0 (No malicious items detected) (end)
Hi, Go ahead and run Malwarebytes again, delete those items and post a fresh log. As for the items in Trend Micro go ahead and leave those alone for now. :)
Good Morning! Ran another malawarebytes: Malwarebytes Anti-Malware 1.62.0.1300 www.malwarebytes.org Database version: v2012.07.18.10 Windows 7 Service Pack 1 x64 NTFS Internet Explorer 9.0.8112.16421 DARLENE'S :: DARLENES-PC [administrator] 7/19/2012 6:06:36 AM mbam-log-2012-07-19 (06-24-32).txt Scan type: Quick scan Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM Scan options disabled: P2P Objects scanned: 254805 Time elapsed: 17 minute(s), 33 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 2 HKCR\Interface\{77777777-7777-7777-7777-770077227758} (Adware.GamePlayLab) -> No action taken. HKCR\TypeLib\{44444444-4444-4444-4444-440044224458} (Adware.GamePlayLab) -> No action taken. Registry Values Detected: 0 (No malicious items detected) Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 0 (No malicious items detected) Files Detected: 0 (No malicious items detected) (end) So where does this carp** come from? How do those adwares get into my system?? Now what? dar

Hi,

Are you or anyone using the computer on gaming sites at all?



Good Morning!

No - I am the only user on my lap top, and I do not like games. I do not play them at all. :angry:

Maybe Trend Micro is not the best anti virus software to have…..my husband has Kaspersky on his tower. Or maybe I need to upgrade to a better version of Trend. what do ya recommend?

I'm off to work……

Dar
Hi, Ok…when you get back I will have more instructions for you…I am going to figure this out so we can nip this one. :) As for antivirus programs….I usually only recommend Avast (what I use) and Microsoft Security Essentials. If you would like to try either of those when we are done I can get you the links. :)
Hi, Go ahead and run a Full Scan with Malwarebytes and when complete delete anything found. Then run a Quick Scan as well. Post the logs that are made to your next reply. :)

Hi,

Go ahead and run a Full Scan with Malwarebytes and when complete delete anything found. Then run a Quick Scan as well.

Post the logs that are made to your next reply. :)


Good Morning Jeff!

We had a staff meeting last night, so didn't get home till 9:30pm - Trend Micro is set to do a full scan every night at 9:45pm - so I let it run. I get up this morning and this is the screen I seen. thought I'd attach it. I will run the malawarebytes this weekend. Friday's are just too busy here.

thanks for all your help!

Dar
Hi, I think that Trend Micro is picking up some of the quarantined files that are still on your system. Whenever you get the Malwarebytes scan completed just go ahead and post that. There is no hurry, but if you need more time please let me know. :)
Good Morning Jeff! Happy Friday! I certainly hope so! I feel so violated anymore!!! we are not riding this weekend, or he hasn't told me yet!!!! I should be able to do this this weekend. No problem! cya soon! Dar
I ran Malawarebytes last night - here are the results; Malwarebytes Anti-Malware 1.62.0.1300 www.malwarebytes.org Database version: v2012.07.18.10 Windows 7 Service Pack 1 x64 NTFS Internet Explorer 9.0.8112.16421 DARLENE'S :: DARLENES-PC [administrator] 7/20/2012 5:37:52 PM mbam-log-2012-07-21 (06-54-39).txt Scan type: Full scan (C:\|) Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM Scan options disabled: P2P Objects scanned: 654682 Time elapsed: 6 hour(s), 36 minute(s), 28 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 0 (No malicious items detected) Registry Values Detected: 0 (No malicious items detected) Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 0 (No malicious items detected) Files Detected: 9 C:\Program Files\Trend Micro\Internet Security\Temp\VS060UF2.PIC (Extension.Mismatch) -> No action taken. C:\Program Files\Trend Micro\Internet Security\Temp\VS500FU6.PIC (Extension.Mismatch) -> No action taken. C:\Program Files\Trend Micro\Internet Security\Temp\VSDM049M.PIC (Extension.Mismatch) -> No action taken. C:\Program Files\Trend Micro\Internet Security\Temp\VSKU13R0.PIC (Extension.Mismatch) -> No action taken. C:\Program Files (x86)\iBryte\browseforchange\iBryteDesktop.exe (Adware.IBryte) -> No action taken. C:\Qoobox\Quarantine\C\Program Files (x86)\I Want This\I Want This.exe.vir (Adware.GamePlayLabs) -> No action taken. C:\Qoobox\Quarantine\C\Program Files (x86)\I Want This\I Want ThisGui.exe.vir (Adware.GamePlayLabs) -> No action taken. C:\Qoobox\Quarantine\C\Program Files (x86)\I Want This\Uninstall.exe.vir (Adware.GamePlayLabs) -> No action taken. C:\Users\DARLENE'S\AppData\LocalLow\iBryte\Implementations\browseforchange\Assemblies\1\BrowserObjects.dll (Adware.IBryte) -> No action taken. (end) After I saved the log, I removed the threats as instructed. Now I have to run it again as a quick scan…bbl! dar
Good Morning! Here is the quick scan results: Malwarebytes Anti-Malware 1.62.0.1300 www.malwarebytes.org Database version: v2012.07.18.10 Windows 7 Service Pack 1 x64 NTFS Internet Explorer 9.0.8112.16421 DARLENE'S :: DARLENES-PC [administrator] 7/21/2012 7:11:19 AM mbam-log-2012-07-21 (07-11-19).txt Scan type: Quick scan Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM Scan options disabled: P2P Objects scanned: 254988 Time elapsed: 23 minute(s), 52 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 0 (No malicious items detected) Registry Values Detected: 0 (No malicious items detected) Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 0 (No malicious items detected) Files Detected: 0 (No malicious items detected) (end) I'm home all day……bummer!! dar

Looks good. How is the system running? :)



Good Morning Jeff!

so far things seem to "normal" - no more pop up boxes from Trend about trojans, etc. But where do these game adwares come from? How can these and others be better blocked?

Dar

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI