This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] very slow, unresponsive and freezes up laptop

43 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

OTL log All processes killed ========== PROCESSES ========== No active process named explorer.exe was found! ========== OTL ========== Service gusvc stopped successfully! Service gusvc deleted successfully! Service LiveUpdate stopped successfully! Service LiveUpdate deleted successfully! C:\Program Files\Symantec\LiveUpdate\LuComServer_3_0.EXE moved successfully. Service Automatic LiveUpdate Scheduler stopped successfully! Service Automatic LiveUpdate Scheduler deleted successfully! C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe moved successfully. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7E853D72-626A-48EC-A868-BA8D5E23E045}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7E853D72-626A-48EC-A868-BA8D5E23E045}\ not found. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{4982D40A-C53B-4615-B15B-B5B5E98D167C} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4982D40A-C53B-4615-B15B-B5B5E98D167C}\ not found. Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser\\{C4069E3A-68F1-403E-B40E-20066696354B} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C4069E3A-68F1-403E-B40E-20066696354B}\ not found. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\KernelFaultCheck deleted successfully. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\My Web Search Bar deleted successfully. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{d8e32852-a757-11dc-a403-00038a000015}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{d8e32852-a757-11dc-a403-00038a000015}\ not found. File E:\Autorun.exe not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{d8e32852-a757-11dc-a403-00038a000015}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{d8e32852-a757-11dc-a403-00038a000015}\ not found. File E:\Autorun.exe not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{d8e32852-a757-11dc-a403-00038a000015}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{d8e32852-a757-11dc-a403-00038a000015}\ not found. File E:\Autorun.exe not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{d8e32852-a757-11dc-a403-00038a000015}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{d8e32852-a757-11dc-a403-00038a000015}\ not found. File E:\Autorun.exe not found. C:\sqmnoopt05.sqm moved successfully. C:\sqmdata05.sqm moved successfully. C:\sqmnoopt04.sqm moved successfully. C:\sqmdata04.sqm moved successfully. C:\sqmdata03.sqm moved successfully. C:\sqmnoopt03.sqm moved successfully. ========== COMMANDS ========== [EMPTYTEMP] User: All Users User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: g ->Temp folder emptied: 1313934 bytes ->Temporary Internet Files folder emptied: 33170 bytes ->Java cache emptied: 0 bytes ->FireFox cache emptied: 49160755 bytes User: LocalService ->Temp folder emptied: 65984 bytes ->Temporary Internet Files folder emptied: 33170 bytes User: michele User: NetworkService ->Temp folder emptied: 2910 bytes ->Temporary Internet Files folder emptied: 33170 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes Windows Temp folder emptied: 68182 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes RecycleBin emptied: 0 bytes Total Files Cleaned = 48.36 mb OTL by OldTimer - Version 3.1.12.0 log created on 12092009_233844 Files\Folders moved on Reboot… File\Folder C:\WINDOWS\temp\Perflib_Perfdata_c4.dat not found! Registry entries deleted on Reboot… ================================================================================ ==================== Kerpinsky is requiring Java script enabled.I did check at internet options and it is enabled.but it is still not scaning
All processes killed ========== PROCESSES ========== No active process named explorer.exe was found! ========== OTL ========== Service gusvc stopped successfully! Service gusvc deleted successfully! Service LiveUpdate stopped successfully! Service LiveUpdate deleted successfully! C:\Program Files\Symantec\LiveUpdate\LuComServer_3_0.EXE moved successfully. Service Automatic LiveUpdate Scheduler stopped successfully! Service Automatic LiveUpdate Scheduler deleted successfully! C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe moved successfully. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7E853D72-626A-48EC-A868-BA8D5E23E045}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7E853D72-626A-48EC-A868-BA8D5E23E045}\ not found. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{4982D40A-C53B-4615-B15B-B5B5E98D167C} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4982D40A-C53B-4615-B15B-B5B5E98D167C}\ not found. Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser\\{C4069E3A-68F1-403E-B40E-20066696354B} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C4069E3A-68F1-403E-B40E-20066696354B}\ not found. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\KernelFaultCheck deleted successfully. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\My Web Search Bar deleted successfully. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{d8e32852-a757-11dc-a403-00038a000015}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{d8e32852-a757-11dc-a403-00038a000015}\ not found. File E:\Autorun.exe not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{d8e32852-a757-11dc-a403-00038a000015}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{d8e32852-a757-11dc-a403-00038a000015}\ not found. File E:\Autorun.exe not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{d8e32852-a757-11dc-a403-00038a000015}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{d8e32852-a757-11dc-a403-00038a000015}\ not found. File E:\Autorun.exe not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{d8e32852-a757-11dc-a403-00038a000015}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{d8e32852-a757-11dc-a403-00038a000015}\ not found. File E:\Autorun.exe not found. C:\sqmnoopt05.sqm moved successfully. C:\sqmdata05.sqm moved successfully. C:\sqmnoopt04.sqm moved successfully. C:\sqmdata04.sqm moved successfully. C:\sqmdata03.sqm moved successfully. C:\sqmnoopt03.sqm moved successfully. ========== COMMANDS ========== [EMPTYTEMP] User: All Users User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: g ->Temp folder emptied: 1313934 bytes ->Temporary Internet Files folder emptied: 33170 bytes ->Java cache emptied: 0 bytes ->FireFox cache emptied: 49160755 bytes User: LocalService ->Temp folder emptied: 65984 bytes ->Temporary Internet Files folder emptied: 33170 bytes User: michele User: NetworkService ->Temp folder emptied: 2910 bytes ->Temporary Internet Files folder emptied: 33170 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes Windows Temp folder emptied: 68182 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes RecycleBin emptied: 0 bytes Total Files Cleaned = 48.36 mb OTL by OldTimer - Version 3.1.12.0 log created on 12092009_233844 Files\Folders moved on Reboot… File\Folder C:\WINDOWS\temp\Perflib_Perfdata_c4.dat not found! Registry entries deleted on Reboot… ================================================================================ ====================== Kerpinsky is requiring Java script enabled.I chcked the browser option and it is enabled.still it is not scaning.
almar,

Let's try a different online scan:

ESET Online Scanner:

Note: You can use either Internet Explorer or Mozilla FireFox for this scan. You will however need to disable your current installed Anti-Virus, how to do so can be read here.

Vista users: You will need to to right-click on the either the IE or FF icon in the Start Menu or Quick Launch Bar on the Taskbar and select Run as Administrator from the context menu.

  • Please go here then click on: [external image: Posted Image]

    Note: If using Mozilla Firefox you will need to download esetsmartinstaller_enu.exe when prompted then double click on it to install.
    All of the below instructions are compatible with either Internet Explorer or Mozilla FireFox.

  • Select the option YES, I accept the Terms of Use then click on: [external image: Posted Image]
  • When prompted allow the Add-On/Active X to install.
  • Make sure that the option Remove found threats is NOT checked, and the option Scan archives is checked.
  • Now click on Advanced Settings and select the following:
    • Scan for potentially unwanted applications
    • Scan for potentially unsafe applications
    • Enable Anti-Stealth Technology
  • Now click on: [external image: Posted Image]
  • The virus signature database… will begin to download. Be patient this make take some time depending on the speed of your Internet Connection.
  • When completed the Online Scan will begin automatically.
  • Do not touch either the Mouse or keyboard during the scan otherwise it may stall.
  • When completed select Uninstall application on close if you so wish, make sure you copy the logfile first!
  • Now click on: [external image: Posted Image]
  • Use notepad to open the logfile located at C:\Program Files\ESET\EsetOnlineScanner\log.txt.
  • Copy and paste that log as a reply to this topic.

Note: Do not forget to re-enable your Anti-Virus application after running the above scan!
Hi TomK I am using another computer to write this. The previous actions taken had made the computer worse and nonfunctional. It did not shut down when doing the right procedure.Now it is not responding.An error message comes out {Application Error: the application failed to initialize properly 0x000012d. the wireless Network connection window is opening for some reason.It is just frozen up. I am very disappointed.
almar,

Restart your computer.
When the machine first starts again it will generally list some equipment that is installed in your machine,
amount of memory, hard drives installed etc (BOOT SCREEEN).
At this point you should gently tap the F8 key repeatedly until you are presented with a Options menu.
Select the option for Last Known Good Configuration using the arrow keys.
Then press enter on your keyboard to boot.

Let me know if you are back into your computer.
Hi TomK I got the Eset log eventually after a 4 hour scan! ESETSmartInstaller@High as CAB hook log: OnlineScanner.ocx - registred OK # version=7 # iexplore.exe=6.00.2900.2180 (xpsp_sp2_rtm.040803-2158) # OnlineScanner.ocx=1.0.0.6211 # api_version=3.0.2 # EOSSerial=d2adf7b46934f941b2133330c77555e6 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=true # unsafe_checked=true # antistealth_checked=true # utc_time=2009-12-11 03:34:31 # local_time=2009-12-10 10:34:31 (-0500, Eastern Standard Time) # country="United States" # lang=1033 # osver=5.1.2600 NT Service Pack 2 # compatibility_mode=769 16775141 100 98 0 195845302 0 0 # compatibility_mode=6143 16777215 0 0 0 0 0 0 # compatibility_mode=8192 67108863 100 0 0 0 0 0 # scanned=54588 # found=1 # cleaned=0 # scan_time=13138 C:\Program Files\MSN Messenger\riched20.dll Win32/FunWeb application 00000000000000000000000000000000 I
almar,

New plan:

Please download Dr.Web CureIt . Save it to your desktop:
  • Doubleclick the drweb-cureit.exe file and click Scan to run express scan. Click OK in the pop-up window to allow the scan.
  • This will scan the files currently running in memory and if something is found, click the Yes button when it asks you if you want to cure it. This is only a short scan.
  • Once the short scan has finished, select Complete scan.
  • Click the green arrow [external image: Posted Image] at the right, and the scan will start.
  • Click Yes to all if it asks if you want to cure/move the file.
  • When the scan has finished, in the menu, click File and choose Save report list
  • Save the report to your desktop. The report will be called DrWeb.csv
  • Note:this report may need to be renamed to Dr.Web.txt in order to post it on the forum.
  • Please post the Dr.Web.txt report in your next reply
  • Close Dr.Web Cureit.
  • Important! Reboot your computer because it could be possible that files in use will be moved/deleted during reboot.

NOTE. During the scan, pop-up window will open asking for full version purchase. Simply close the window by clicking on the X in the upper right corner.
I ran Dr.Web but after scanning for about 7 hours it just stops dead.I did that again and the same thing happened .So far it found 5 possible trojans .It would not go any farther. What's to do next? shall I just search for them and delete them? some are .DLL files and some are .exe.
Hi TomK I ran DrWeb again.WoW it took 12 hours to complete the scan. Here is DrWeb report: inst.exe;C:\Documents and Settings\All Users\Application Data\AOL Downloads\ssc_suite_installer\210.5.4.4\suite;Probably BACKDOOR.Trojan;; inst.exe;C:\Program Files\AOL\Installers\AOL Safety & Security Center 1.02;Probably BACKDOOR.Trojan;; setup.exe;C:\Program Files\Common Files\AOL\Backup\ACS\Current\Suite;Probably BACKDOOR.Trojan;; riched20.dll;C:\Program Files\MSN Messenger;Adware.Msearch;; A0194383.exe\data004;C:\System Volume Information\_restore{D5341F9C-33F7-43CF-8BD2-1AE937C9BA1B}\RP961\A0194383.exe;Probably BACKDOOR.Trojan;; A0194383.exe;C:\System Volume Information\_restore{D5341F9C-33F7-43CF-8BD2-1AE937C9BA1B}\RP961;Archive contains infected objects;Moved.; A0194384.exe/data004\data007;C:\System Volume Information\_restore{D5341F9C-33F7-43CF-8BD2-1AE937C9BA1B}\RP961\A0194384.exe/data004;Probably BACKDOOR.Trojan;; data004;C:\System Volume Information\_restore{D5341F9C-33F7-43CF-8BD2-1AE937C9BA1B}\RP961;Archive contains infected objects;; A0194384.exe;C:\System Volume Information\_restore{D5341F9C-33F7-43CF-8BD2-1AE937C9BA1B}\RP961;Archive contains infected objects;Moved.; A0194388.exe\data004;C:\System Volume Information\_restore{D5341F9C-33F7-43CF-8BD2-1AE937C9BA1B}\RP961\A0194388.exe;Probably BACKDOOR.Trojan;; A0194388.exe;C:\System Volume Information\_restore{D5341F9C-33F7-43CF-8BD2-1AE937C9BA1B}\RP961;Archive contains infected objects;Moved.; A0194389.exe/data004\data007;C:\System Volume Information\_restore{D5341F9C-33F7-43CF-8BD2-1AE937C9BA1B}\RP961\A0194389.exe/data004;Probably BACKDOOR.Trojan;; data004;C:\System Volume Information\_restore{D5341F9C-33F7-43CF-8BD2-1AE937C9BA1B}\RP961;Archive contains infected objects;; A0194389.exe;C:\System Volume Information\_restore{D5341F9C-33F7-43CF-8BD2-1AE937C9BA1B}\RP961;Archive contains infected objects;Moved.;
almar,

Please download exeHelper to your desktop.
Double-click on exeHelper.com to run the fix.
A black window should pop up, press any key to close once the fix is completed.
Post the contents of exehelperlog.txt (Will be created in the directory where you ran exeHelper.com, and should open at the end of the scan)
Note: If the window shows a message that says "Error deleting file", please re-run the program before posting a log - and post the two logs together (they will both be in the one file).

Then please attempt to run ComboFix again.
TomK You havn't mentioned what actions to take with the files found by the DrWeb scan .I havn't selected them or moved or deleted them after the outcome of the scan .Do i need to do any of that rght now before folowing your latest instructions on the ExeHelper??
almar, Sorry about that. The ones in system restore we will clean out when we are done. The others are a false positive. You don't need to do anything with them.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI