Welcome guest. Before posting on our computer help forum, you must register. Click here it's easy and free.

Author Topic: PC Running Very Slow/Freezing  (Read 12199 times)

0 Members and 1 Guest are viewing this topic.

bluecountry

    Topic Starter


    Apprentice

    Thanked: 1
    PC Running Very Slow/Freezing
    « on: June 02, 2011, 10:22:03 AM »
    My other PC I am using, is having major issues.
    Overall, it is running very slow.  Opening up the browser (Mozilla and IE) can be slow, as can opening up Microsoft Word.
    To makes matters worse, it frequently, crash, freeze, and Mozilla will boot me off.

    Heck it was a pain even getting these logs!

    When following the steps, for example, I could not verify Java.  When I clicked on the links in Mozilla, then clicked verify, I was booted off.  When I did it with internet explorer, it froze.  So Java is unverified.

    Overall, it crashes, it is painful slow.
    Oh, and I deleted AOL and Verizon, yet they still show up in the taskbar options.

    If someone can look over the logs, let me know what is wrong, and if we can somehow completely rid the PC of aol/verizon and verify java, that would be awesome.

    Thanks.

    [recovering disk space - old attachment deleted by admin]

    SuperDave

    • Malware Removal Specialist


    • Genius
    • Thanked: 1020
    • Certifications: List
    • Experience: Expert
    • OS: Windows 10
    Re: PC Running Very Slow/Freezing
    « Reply #1 on: June 02, 2011, 04:27:19 PM »
    Hello and welcome to Computer Hope Forum. My name is Dave. I will be helping you out with your particular problem on your computer.

    1. I will be working on your Malware issues. This may or may not solve other issues you have with your machine.
    2. The fixes are specific to your problem and should only be used for this issue on this machine.
    3. If you don't know or understand something, please don't hesitate to ask.
    4. Please DO NOT run any other tools or scans while I am helping you.
    5. It is important that you reply to this thread. Do not start a new topic.
    6. Your security programs may give warnings for some of the tools I will ask you to use. Be assured, any links I give are safe.
    7. Absence of symptoms does not mean that everything is clear.

    If you can't access the internet with your infected computer you will have to download and transfer any programs to the computer you're using now and transfer them to the infected computer with a CD-RW or a USB storage device. I prefer a CD because a storage device can get infected. If you use a storage device hold the shift key down while inserting the USB storage device for about 10 secs. You will also have to transfer the logs you receive back to the good computer using the same method until we can get the computer back on-line.
    ************************************************
    Please do not attach your logs unless absolutely necessary. Copy and paste them in your reply(ies)

    **************************************************
    You have Viewpoint installed.

    Viewpoint Media Player/Manager/Toolbar is considered as Foistware instead of malware since it is installed without users approval but doesn't spy or do anything "bad".

    More information:

    * ViewMgr.exe - Useless
    * Viewpoint to Plunge Into Adware

    It is suggested to remove the program now. Go to Start > Control Panel > Add/Remove Programs - (Vista & Win7 is Programs and Features) and remove the following programs if present.

    * Viewpoint
    * Viewpoint Manager
    * Viewpoint Media Player
    * Viewpoint Toolbar
    * Viewpoint Experience Technology

    *******************************************************
    Download Disable/Remove Windows Messenger to the desktop to remove Windows Messenger.

    Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Unzip the file on the desktop. Open the MessengerDisable.exe and choose the bottom box - Uninstall Windows Messenger and click Apply.

    Exit out of MessengerDisable then delete any files that were put on the desktop.
    *******************************************************
    Open HijackThis and select Do a system scan only

    Place a check mark next to the following entries: (if there)

    R3 - URLSearchHook: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
    O2 - BHO: (no name) - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - (no file)
    O2 - BHO: (no name) - {9D425283-D487-4337-BAB6-AB8354A81457} - (no file)
    O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe


    Important: Close all open windows except for HijackThis and then click Fix checked.

    Once completed, exit HijackThis.
    ******************************************************
    Download Security Check by screen317 from one of the following links and save it to your desktop.

    Link 1
    Link 2

    * Unzip SecurityCheck.zip and a folder named Security Check should appear.
    * Open the Security Check folder and double-click Security Check.bat
    * Follow the on-screen instructions inside of the black box.
    * A Notepad document should open automatically called checkup.txt
    * Post the contents of that document in your next reply.

    Note: If a security program requests permission from dig.exe to access the Internet, allow it to do so.
    ******************************************************
    Download DDS from HERE or HERE and save it to your desktop.

    Vista users right click on dds and select Run as administrator (you will receive a UAC prompt, please allow it)

    * XP users Double click on dds to run it.
    * If your antivirus or firewall try to block DDS then please allow it to run.
    * When finished DDS will open two (2) logs.

    1) DDS.txt
    2) Attach.txt

    * Save both logs to your desktop.
    * Please copy and paste the entire contents of both logs in your next reply.

    Note: DDS will instruct you to post the Attach.txt log as an attachment.
    Please just post it as you would any other log by copying and pasting it into the reply.
    Windows 8 and Windows 10 dual boot with two SSD's

    bluecountry

      Topic Starter


      Apprentice

      Thanked: 1
      Re: PC Running Very Slow/Freezing
      « Reply #2 on: June 05, 2011, 05:55:45 PM »
      OK...thank you very much.
      Here is my progress:



      1)  Was able to remove viewpoint.
      2)  Followed windows messenger instructions, should be gone.
      3)  Followed directions for hijack this, should be fixed.
      4)  Followed and attached log from Security Check by screen317.
      5)  DDS is where it got tricky.
      -I tried following your directions and links, but when I clicked the first link and ran the program, all that attached was some funny log with weird characters (I am not allowed to attach it).
      -I clicked the second link, all it did was open up a webpage with weird characters http://www.forospyware.com/sUBs/dds/dds.pif


      So what does this mean and what should I do?

      I'd like to ask as well....
      1)  The security check I downloaded, how do I remove this program?
      2)  DDS, how do I remove this program?
      3)  Now with viewpoint and windows messenger, I believe I deleted them.  I did so at least in my XP user name, but I have other people on this PC who have user names, if I remove it from one, is it removed from all?

      4)  I really want to get rid of verizon, which has no business on my pc any longer. 
      (Verizon Online Help and Support + Verizon Yahoo! Applications)
      -I try to remove it by going to all programs...when I do though it just freezes and stops.  Why?  What can I do to rid the PC of this?

      5) PC still ain't running great, what can be done?

      Thanks.

      [recovering disk space - old attachment deleted by admin]

      SuperDave

      • Malware Removal Specialist


      • Genius
      • Thanked: 1020
      • Certifications: List
      • Experience: Expert
      • OS: Windows 10
      Re: PC Running Very Slow/Freezing
      « Reply #3 on: June 06, 2011, 04:11:06 PM »
      Quote
      So what does this mean and what should I do?
      We'll use another scanner.

      Quote
      The security check I downloaded, how do I remove this program?
      You can delete it or drag it into your Recycling bin. The same for DDS

      Quote
      but I have other people on this PC who have user names, if I remove it from one, is it removed from all?
      If you're the Administrator and you've put restrictions on their accounts, it's possible they didn't install it. I really depends on what access they had with their accounts.
      Quote
      I really want to get rid of verizon, which has no business on my pc any longer. 
      (Verizon Online Help and Support + Verizon Yahoo! Applications)
      Let's continue with the cleaning. Please remind me about this after we're finished.

      Update Your Java (JRE)

      Old versions of Java have vulnerabilities that malware can use to infect your system.


      First Verify your Java Version

      If there are any other version(s) installed then update now.

      Get the new version (if needed)

      If your version is out of date install the newest version of the Sun Java Runtime Environment.

      Note: UNCHECK any pre-checked toolbar and/or software offered with the Java update. The pre-checked toolbars/software are not part of the Java update.

      Be sure to close ALL open web browsers before starting the installation.

      Remove any old versions

      1. Download JavaRa and unzip the file to your Desktop.
      2. Open JavaRA.exe and choose Remove Older Versions
      3. Once complete exit JavaRA.

      Additional Note: The Java Quick Starter (JQS.exe) adds a service to improve the initial startup time of Java applets and applications. To disable the JQS service if you don't want to use it, go to Start > Control Panel > Java > Advanced > Miscellaneous and uncheck the box for Java Quick Starter. Click OK and reboot your computer.
      ****************************************************
      Please download ComboFix from BleepingComputer.com

      Alternate link: GeeksToGo.com

      and save it to your Desktop.
      It would be easiest to download using Internet Explorer.
      If you insist on using Firefox, make sure that your download settings are as follows:

      * Tools->Options->Main tab
      * Set to "Always ask me where to Save the files".

      Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools A guide to do this can be found here
      Double click ComboFix.exe & follow the prompts.
      As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
      Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console

      Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

      Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:


      Click on Yes, to continue scanning for malware.
      When finished, it shall produce a log for you.  Please include the contents of C:\ComboFix.txt in your next reply.

      If you have problems with ComboFix usage, see How to use ComboFix
      Windows 8 and Windows 10 dual boot with two SSD's

      bluecountry

        Topic Starter


        Apprentice

        Thanked: 1
        Re: PC Running Very Slow/Freezing
        « Reply #4 on: June 07, 2011, 11:40:51 PM »
        Well, I hate to make your job harder but..............


        I tried the java link on both mozilla and ie.
        On mozilla, the browser crashed both times, and on ie the browser froze.

        Can't do the java steps, should I just go to combofix and skip for the time being?

        SuperDave

        • Malware Removal Specialist


        • Genius
        • Thanked: 1020
        • Certifications: List
        • Experience: Expert
        • OS: Windows 10
        Re: PC Running Very Slow/Freezing
        « Reply #5 on: June 08, 2011, 12:57:52 PM »
        Quote
        Can't do the java steps, should I just go to combofix and skip for the time being?
        Yes, please.
        Windows 8 and Windows 10 dual boot with two SSD's

        bluecountry

          Topic Starter


          Apprentice

          Thanked: 1
          Re: PC Running Very Slow/Freezing
          « Reply #6 on: June 10, 2011, 05:31:17 PM »
          Log, to the best of my ability

          [recovering disk space - old attachment deleted by admin]

          SuperDave

          • Malware Removal Specialist


          • Genius
          • Thanked: 1020
          • Certifications: List
          • Experience: Expert
          • OS: Windows 10
          Re: PC Running Very Slow/Freezing
          « Reply #7 on: June 10, 2011, 05:39:25 PM »
          The log shows that you have two AV programs running on your computer which is a no-no. Either McAfee Anti-Virus and Anti-Spyware or ThreatFire will have to be disabled.

          Please do not attach your logs unless absolutely necessary. Copy and paste them in your reply(ies)

          * Download the following tool: RootRepeal - Rootkit Detector
          * Direct download link is here: RootRepeal.zip

          * Close all programs and temporarily disable your anti-virus, Firewall and any anti-malware real-time protection before performing a scan.
          * Click this link to see a list of such programs and how to disable them.

          * Extract the program file to a new folder such as C:\RootRepeal
          * Run the program RootRepeal.exe and go to the REPORT tab and click on the Scan button.
          * Select ALL of the checkboxes and then click OK and it will start scanning your system.
          * If you have multiple drives you only need to check the C: drive or the one Windows is installed on.
          * When done, click on Save Report
          * Save it to the same location where you ran it from, such as C:RootRepeal
          * Save it as rootrepeal.txt
          * Then open that log and select all and copy/paste it back on your next reply please.
          * Close RootRepeal.
          Windows 8 and Windows 10 dual boot with two SSD's

          bluecountry

            Topic Starter


            Apprentice

            Thanked: 1
            Re: PC Running Very Slow/Freezing
            « Reply #8 on: June 10, 2011, 11:14:53 PM »
            Thanks Dave, few questions.

            1)  Yea I saw threatfire, I never heard of it and do not know why I have it.  I'd like it removed, if not at least turned off...yet I cannot find the program under add/remove programs...do you know how I can find it, and remove it?

            2)  Before I do the scan, if we can get rid of threatfire I will shut off McAfee...but how can I find out if I have any other firewalls, virus, or malware scans running just to be sure?
            Thanks.

            SuperDave

            • Malware Removal Specialist


            • Genius
            • Thanked: 1020
            • Certifications: List
            • Experience: Expert
            • OS: Windows 10
            Re: PC Running Very Slow/Freezing
            « Reply #9 on: June 11, 2011, 06:09:39 PM »
            Quote
            if we can get rid of threatfire I will shut off McAfee...but how can I find out if I have any other firewalls, virus, or malware scans running just to be sure?
            Try removing it this way. All the protection programs are list at the top of the ComboFix log.

            Re-running ComboFix to remove infections:

            • Close any open browsers.
            • Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
            • Open notepad and copy/paste the text in the quotebox below into it:
              Quote
              KillAll::

              SecCenter::
              67B2B9A1-25C8-4057-962D-807958FFC9E3

            • Save this as CFScript.txt, in the same location as ComboFix.exe



            • Referring to the picture above, drag CFScript into ComboFix.exe
            • When finished, it shall produce a log for you at C:\ComboFix.txt
            • I don't need to see the log from this.
            Windows 8 and Windows 10 dual boot with two SSD's

            bluecountry

              Topic Starter


              Apprentice

              Thanked: 1
              Re: PC Running Very Slow/Freezing
              « Reply #10 on: June 20, 2011, 11:25:28 AM »
              OK...I went ahead and ran the scan (I can give you the log if wanted, I have the first log saved for you as well).
              Now what?

              1) Is the PC safe, is there anyway to check?

              2) Verizon Online Help and support....when I try to remove this program through control panel/add remove programs, I go through a few steps and it freezes, anyway I can get it off the PC?

              3) Verizon Yahoo Applications....same deal.

              4) I have attached a doc with a picture.  On my PC, from time to time I get prompted that "files are waiting to be written on a CD" I have NO idea why this happens, and was wondering what this means and if I can do something to get rid of the prompt.


              Thanks!

              [recovering disk space - old attachment deleted by admin]

              SuperDave

              • Malware Removal Specialist


              • Genius
              • Thanked: 1020
              • Certifications: List
              • Experience: Expert
              • OS: Windows 10
              Re: PC Running Very Slow/Freezing
              « Reply #11 on: June 20, 2011, 04:34:30 PM »
              I'm still waiting to see the log from RootRepeal.
              Quote
              I have attached a doc with a picture.  On my PC, from time to time I get prompted that "files are waiting to be written on a CD" I have NO idea why this happens, and was wondering what this means and if I can do something to get rid of the prompt.
              At some point you must have sent some files to your CD/DVD burner. To clear it, just click on the ballon and delete any files that are there.
              Quote
              Is the PC safe, is there anyway to check?
              I won't know that until we've run all the scans including the RootRepeal scan.
              Quote
              Verizon Online Help and support....when I try to remove this program through control panel/add remove programs, I go through a few steps and it freezes, anyway I can get it off the PC?

              3) Verizon Yahoo Applications....same deal.
              Let's try this: Look for the Verizon programs and see if you can uninstall them.

              Delete An Uninstall Entry

              •Start HijackThis

              •Click on the Open the Misc Tools section

              •Click on the Open Uninstall Manager button.

              •Highlight the entry you want to remove.
              •Click Delete this entry
              Windows 8 and Windows 10 dual boot with two SSD's

              bluecountry

                Topic Starter


                Apprentice

                Thanked: 1
                Re: PC Running Very Slow/Freezing
                « Reply #12 on: June 22, 2011, 11:02:59 PM »
                LOL my bad!
                I totally forgot about the rootrepeal (will have that for you shortly).

                I DID follow the instructions however for hijack this to delete
                -AOL icon
                -Verizon

                I was able to delete the entry in hijack this, when I went to add/remove programs to see if they were gone; they were!
                Thanks.
                Log coming........

                bluecountry

                  Topic Starter


                  Apprentice

                  Thanked: 1
                  Re: PC Running Very Slow/Freezing
                  « Reply #13 on: June 24, 2011, 02:45:29 PM »
                  OK...ran the scan.


                  Log below:
                  Quote
                  ROOTREPEAL (c) AD, 2007-2009
                  ==================================================
                  Scan Start Time:      2011/06/24 16:18
                  Program Version:      Version 1.3.5.0
                  Windows Version:      Windows XP Media Center Edition SP3
                  ==================================================

                  Drivers
                  -------------------
                  Name: dump_atapi.sys
                  Image Path: C:\WINDOWS\System32\Drivers\dump_atapi.sys
                  Address: 0xAA3BB000   Size: 98304   File Visible: No   Signed: -
                  Status: -

                  Name: dump_WMILIB.SYS
                  Image Path: C:\WINDOWS\System32\Drivers\dump_WMILIB.SYS
                  Address: 0xF7BAC000   Size: 8192   File Visible: No   Signed: -
                  Status: -

                  Name: Fs_Rec.SYS
                  Image Path: C:\WINDOWS\System32\Drivers\Fs_Rec.SYS
                  Address: 0xF7BCC000   Size: 7936   File Visible: -   Signed: -
                  Status: Hidden from the Windows API!

                  Name: Mup.sys
                  Image Path: Mup.sys
                  Address: 0xF7367000   Size: 105472   File Visible: -   Signed: -
                  Status: Hidden from the Windows API!

                  Name: Ntfs.sys
                  Image Path: Ntfs.sys
                  Address: 0xF73AE000   Size: 574976   File Visible: -   Signed: -
                  Status: Hidden from the Windows API!

                  Name: rootrepeal.sys
                  Image Path: C:\WINDOWS\system32\drivers\rootrepeal.sys
                  Address: 0xAA173000   Size: 49152   File Visible: No   Signed: -
                  Status: -

                  Name: tcpip.sys
                  Image Path: C:\WINDOWS\system32\DRIVERS\tcpip.sys
                  Address: 0xAA577000   Size: 361600   File Visible: -   Signed: -
                  Status: Hidden from the Windows API!

                  Hidden/Locked Files
                  -------------------
                  Path: C:\hiberfil.sys
                  Status: Locked to the Windows API!

                  Path: c:\windows\temp\mcafee_1bymr1wlmgpoydb
                  Status: Allocation size mismatch (API: 4096, Raw: 0)

                  SSDT
                  -------------------
                  #: 041   Function Name: NtCreateKey
                  Status: Hooked by "Lbd.sys" at address 0xf76ce87e

                  #: 247   Function Name: NtSetValueKey
                  Status: Hooked by "Lbd.sys" at address 0xf76cec10

                  #: 257   Function Name: NtTerminateProcess
                  Status: Hooked by "C:\Program Files\SUPERAntiSpyware\SASKUTIL.sys" at address 0xaa4dc620

                  ==EOF==


                  B. Here is the log

                  SuperDave

                  • Malware Removal Specialist


                  • Genius
                  • Thanked: 1020
                  • Certifications: List
                  • Experience: Expert
                  • OS: Windows 10
                  Re: PC Running Very Slow/Freezing
                  « Reply #14 on: June 24, 2011, 04:13:36 PM »
                  I'd like to scan your machine with ESET OnlineScan

                  •Hold down Control and click on the following link to open ESET OnlineScan in a new window.
                  ESET OnlineScan
                  •Click the button.
                  •For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
                  • Click on to download the ESET Smart Installer. Save it to your desktop.
                  • Double click on the icon on your desktop.
                  •Check
                  •Click the button.
                  •Accept any security warnings from your browser.
                  •Check
                  •Push the Start button.
                  •ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
                  •When the scan completes, push
                  •Push , and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
                  •Push the button.
                  •Push
                  A log file will be saved here: C:\Program Files\ESET\ESET Online Scanner\log.txt
                  Windows 8 and Windows 10 dual boot with two SSD's