• Welcome to Overclockers Forums! Join us to reply in threads, receive reduced ads, and to customize your site experience!

Can't boot up Please Help! Toby

Overclockers is supported by our readers. When you click a link to make a purchase, we may earn a commission. Learn More.

toby23ca

New Member
Joined
Nov 22, 2006
When I boot up I loose my screen Spybot, found I believe a run file (run/Zagrebland)
Ive tried Malwarebytes, and it found Trojans and I got rid of them. Still my screen shuts down on startup and I can only get on in safe mode. Can anyone help me? Here is my
Hijackthis report.
StartupList report, 12/15/2009, 6:22:08 PM
StartupList version: 1.52.2
Started from : C:\Documents and Settings\Richard Jaworoski\Desktop\HiJackThis.exe\HijackThis.EXE
Detected: Windows XP SP2 (WinNT 5.01.2600)
Detected: Internet Explorer v7.00 (7.00.6000.16945)
* Using default options
==================================================

Running processes:

C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Documents and Settings\Richard Jaworoski\Desktop\teaTimer\TeaTimer.exe
C:\Program Files\Audacity\Malwarebytes' Anti-Malware\mbam.exe
C:\Program Files\Microsoft Office\Office\WINWORD.EXE
C:\WINDOWS\msagent\AgentSvr.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Documents and Settings\Richard Jaworoski\Desktop\HiJackThis.exe\HijackThis.exe

--------------------------------------------------

Checking Windows NT UserInit:

[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
UserInit = C:\WINDOWS\system32\userinit.exe,

--------------------------------------------------

Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run

MSConfig = C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
avast! = C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
Malwarebytes Anti-Malware (reboot) = "C:\Program Files\Audacity\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript

--------------------------------------------------

Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce

SpybotSnD = "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" /autocheck
Malwarebytes' Anti-Malware = C:\Program Files\Audacity\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent

--------------------------------------------------

Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run

SpybotSD TeaTimer = C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
Sonic RecordNow! = C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
Google Update = "C:\Documents and Settings\Richard Jaworoski\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
ctfmon.exe = C:\WINDOWS\system32\ctfmon.exe

--------------------------------------------------

Shell & screensaver key from C:\WINDOWS\SYSTEM.INI:

Shell=*INI section not found*
SCRNSAVE.EXE=*INI section not found*
drivers=*INI section not found*

Shell & screensaver key from Registry:

Shell=Explorer.exe
SCRNSAVE.EXE=C:\WINDOWS\system32\ssmypics.scr
drivers=*Registry value not found*

Policies Shell key:

HKCU\..\Policies: Shell=*Registry value not found*
HKLM\..\Policies: Shell=*Registry value not found*

--------------------------------------------------


Enumerating Browser Helper Objects:

(no name) - C:\Program Files\Yahoo!\Companion\Installs\cpn2\yt.dll - {02478D38-C3F9-4efb-9B51-7695ECA05670}
(no name) - C:\PROGRA~1\SPYBOT~1\SDHelper.dll - {53707962-6F74-2D53-2644-206D7942484F}

--------------------------------------------------

Enumerating Task Scheduler jobs:

AppleSoftwareUpdate.job
GoogleUpdateTaskUserS-1-5-21-3655830242-299628409-479451402-1006Core.job
GoogleUpdateTaskUserS-1-5-21-3655830242-299628409-479451402-1006UA.job

--------------------------------------------------

Enumerating Winsock LSP files:

NameSpace #4: C:\WINDOWS\system32\wshbth.dll
NameSpace #5: C:\Program Files\Bonjour\mdnsNSP.dll

--------------------------------------------------

Enumerating ShellServiceObjectDelayLoad items:

PostBootReminder: C:\WINDOWS\system32\SHELL32.dll
CDBurn: C:\WINDOWS\system32\SHELL32.dll
WebCheck: C:\WINDOWS\system32\webcheck.dll
SysTray: C:\WINDOWS\system32\stobject.dll

--------------------------------------------------
End of report, 4,598 bytes
Report generated in 0.070 seconds

Command line options:
/verbose - to add additional info on each section
/complete - to include empty sections and unsuspicious data
/full - to include several rarely-important sections
/force9x - to include Win9x-only startups even if running on WinNT
/forcent - to include WinNT-only startups even if running on Win9x
/forceall - to include all Win9x and WinNT startups, regardless of platform
/history - to list version history only
 
Boot from the original CD into the recovery console.

Run: chkdsk/r <--- finds and fixes damaged files and disk sectors

Run: fixmbr <--- makes sure the original boot sector is rewritten

Run: fixboot <--- fixes damaged boot information

reboot
 
I have a sony Vaio VGN-A290 it did not come with a disk,and i did not create recovery disks just stupid i never expected this. I can create them now if you think that will help?
I have an option to hit f10 and it will set my computer back to factory settings i will loose everything thou. Do you know how to get the full Hijackthis log the one which gives me the choices what to deleate to fix? Three anti virus programs don't find any virus on my computer yet this is happening. I go to boot up and a flicker and a image flashes then i have to reboot in safe mode, thats what happens. Thank you so much TOBY
 
Since you can access Safe Mode, try using System Restore (Control Panel--> Performance and Maintenance--> System Restore). Or from the Windows Advanced Options Menu (available after hitting F8 directly after POST), try selecting Last Known Good Configuration.
 
I tried this and also comand promt to reset too another time and no go.And yet all the anti viruses say i don't have a virus,just when i reboot i see and image flash and i am sent to reboot.This is a very smart thing whatever it is!! but i know you guys are smarter
can you please try to help me figure out.If i do a complete system restore i loose alot of stuff. This happend once before and hijsckthis fixed it and i used it blindly,i wqish i understood how to work hijackthis. Thank you so much for your help TOBY
 
I actually have a similar issue on my computer, but it has more to do with windows.
Twas a clean install and it would lock up or black out on the logo screen, and also fry any USB devices attached or cards installed.
Which is now why I use linux.

Throw in a linux LiveCD and backup your data onto something. That'll help if everything else faile.
Reccomend PuppyLinux
 
Your HighJackThis log reports no problematic entries - everything there is normal.

You may want to run Malwarebytes again and see if it finds anything, otherwise, Redduc's advice is the best available - roll back to a system restore at an earlier point.

System restore does not affect any of your personal or saved files, it just rolls the system back to an earlier date - you can reinstall any programs if necessary.

Sounds like someone needs a HD wipe! :eek:

:welcome:

Seeing as your new, I just wanted to let you know that this comment is not helpful and is not what we encourage here.

In the future, consider posting something more helpful, or googling some possible solutions for the thread starter.
 
Last edited:
If it's interacting with the display driver. Try to enter safe mode, and use DriverSweeper to wipe all of the display drivers, reboot, and see if you can get to your desktop. This might buy you the time you need to get your data off. If it works, definitely BACKUP your data. I'm sure you know that now though :)
You might also try using Superantispyware... I've had good luck with it in the past.
 
Back