This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Sysem freezing and going slower [Solved]

46 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi there, I have Windows Vista Home and AVG internet Security 2012 plus other spyware tools, Spybot S&D and Spywareguard but still I found using external tool that I had malware issue (Z-Access) in the machine. I went to make that check seeing that the system is being slower, usually is not very noisy and only sounds like using the coolers when handling a very heavy program (3d Application with real time etc). But these days it sounds a lot and freezes even when using just internet browser or even browsing a folder content. Very often it turns into black squares or all white for a little while and when I turn on the machine it takes longer than usual to reach desktop then flashes to black and white twice (sometimes it happened too that i couldnt enter the desktop and once it even remain blue with just the mouse), then if I reach desktop it goes more or less but not perfect and the continues freezes it suffers make my whole workflow delay a lot. I made a OTL scan and can post its results if needed, but I can try any other stuff you suggest me. Thank you very much in advance for any help =). PS I forgot to mention that lastly AVG declares a lot of potential menaces that seem to be the packages that Spybot downloads when updating so its very strange and Im unsure about removing them or not
Hello asdronin and welcome to the WTT forum.

My name is Satchfan and I would be glad to help you with your computer problem.

Please read the following guidelines which will help to make cleaning your machine easier:
  • please follow all instructions in the order posted
  • please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear
  • all logs/reports, etc. must be posted in Notepad. Please ensure that word wrap is unchecked. In Notepad click Format, uncheck Word wrap if it is checked
  • if you don't understand something, please don't hesitate to ask for clarification before proceeding
  • the fixes are specific to your problem and should only be used for this issue on this machine.
  • please reply within 3 days. If you do not reply within this period I will post a reminder but topics with no reply in 4 days will be closed!
IMPORTANT:

Please DO NOT install/uninstall any programs unless asked to.
Please DO NOT run any scans other than those requested

I will reply shortly with instructions

Satchfan
Hello again asdronin

Run RogueKiller

IMPORTANT: Do not reboot your computer if at all possible otherwise the malware will reactivate and you will have to run RogueKiller again

Download RogueKiller to your desktop.
  • close all running programs
  • for Windows Vista/Seven, right click -> run as administrator, for XP simply double-click on RogueKiller.exe
  • when the prescan is finished, click on Scan
  • the report has been created on the desktop, (or you can click on Report)
  • copy/paste the content in your next post
  • NOTE: DO NOT attempt to remove anything that the scan detects.
If the program is blocked, continue to try it several times. If it still doesn’t work, (it could happen), rename it to winlogon.exe.

===================================================

Run DDS

Please download DDS by sUBs from one of the following links and save it to your desktop.

DDS.pif
DDS.com

  • disable any script blocking protection (How to Disable your Security Programs)
  • double click DDS icon to run the tool (may take up to 3 minutes to run)
  • when done, DDS.txt will open.
  • after a few moments, attach.txt will open in a second window.
  • save both reports to your desktop.
  • Post the contents of the DDS.txt and Attach.txt reports in your next reply
===================================================

Run aswMBR
  • download aswMBR.exe to your desktop.
  • double click aswMBR.exe to run it
  • if asked, accept the AVAST virus definition download
  • click the "Scan" button to start scan
  • on completion of the scan click Save log, save it to your desktop and post in your next reply. Note - do NOT attempt any Fix yet.
Please include the following in your next post :

RKreport.txt
DDS.txt
Attach.txt
aswMBR log


Thanks

Satchfan
Hello Satchfan, and thanks you very much for your reply and guides. Here I attached the files needed and I await your next instructions regarding this trouble. I know I can totally trust the WTT Staff but worrying about the people from outside… could I ask you to remove these files from public view once the problems are fixed? many thanks and if its not possible its fine, this is a great dutty you all are doing helping us to maintain computers clean and safe.
Thanks for the logs.

worrying about the people from outside… could I ask you to remove these files from public view once the problems are fixed?

As this is a public forum we only remove or hide inappropriate or dangerous content from posts.

Your information in the logs cannot be used for anything that could affect you or your computer. However, if you have named documents that you are concerned about being seen publically I suggest you remove them temporarily to a flash drive.


I have looked at your logs and unfortunately one or more of the identified infections is known to use a backdoor trojan.

This allows hackers to remotely control your computer, steal critical system information and download and execute files.

I would advice you to disconnect this PC from the Internet immediately. If you do any banking or other financial transactions on the PC or if it should contain any other sensitive information, please get to a known clean computer and change all passwords where applicable, and it would be wise to contact those same financial institutions to apprise them of your situation.

Though the infection has been identified and because of it's backdoor functionality, your PC is very likely compromised and there is no way to be sure your computer can ever again be trusted. Many experts in the security community believe that once infected with this type of trojan, the best course of action would be a reformat and reinstall of the OS.

Please read these for more information:

How Do I Handle Possible Identify Theft, Internet Fraud and CC Fraud?
http://www.dslreports.com/faq/10451

When Should I Format, How Should I Reinstall
http://www.dslreports.com/faq/10063

These infections can possibly be cleaned, but it will be impossible to be 100% sure that the machine is clean, if this is unacceptable to you then you should consider reformatting both system partitions and reinstalling Windows as this is the only 100% sure answer.

If you wish to reformat then please let me know in your next response, If you decide to go through with the cleanup, please proceed with the following steps:

Download and run ComboFix

Download ComboFix from the following location:

Link

* IMPORTANT !!! Save ComboFix.exe to your Desktop
  • Disable your AntiVirus and AntiSpyware applications, as they may otherwise interfere with our tools. See here for programs that need to be disabled and instruction on how to disable them.
  • Remember to re-enable them when we're done.
  • Double click on ComboFix.exe & follow the prompts.
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

    **Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue its malware removal procedures.

    🖼Click to load external image (Posted Image)


    Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

    🖼Click to load external image (Posted Image)


    Click on Yes, to continue scanning for malware.
Note: Do not mouse-click combofix's window while it is running. That may cause it to stall.

When finished, it will produce a log. Please include the ComboFix.txt in your next reply. It can be found at C:\ComboFix.txt

Satchfan
Hi, Im sorry but I can't format the system if there is another option even if its not 100% secure, I will try to fix this if you don't mind, the trouble is the ammount of sofware installed with all the configuration settings and plugins that I had to set up plus all the data I generated so while its not impossible to format I will try to avoid if you help me and if in the end its not totally fixed I will be very thanked anyway. Here is the Combofix report, however there was a trouble, after Combofix rebooted the system the firewall blocked (probably) a request from Combofix and I wasnt in front of the machine to allow the request (took some hours to complete) so in the Combofix screen I could read "access denied" in the end just before launching the report. Should I re-run the Combofix?

Attachments:

I'm sorry I can't edit the previous post, if you tell me how then I will do next time. I forgot to mention that I rejected to remove the "Home page" and "default search engine" from browser settings, so I think the "access denied" could be due to that.
As you can’t reformat we’ll try to clean it.

I need as much information as possible to help with this so let’s take it a few steps at a time.

Please make sure that ALL your security is disabled, including your firewall and then run ComboFix again.

I also notice that you have run TDSSKiller. Please send a copy of the log: a copy of the log will be saved automatically to the root of the drive (typically C:) called TDSSKiller_*** - (*** denotes version & date)

Thanks

Satchfan
Hi Satchfan, thank you for your patience and efforts in cleaning this machine. Here are the requested files, this time the Combofix didnt reboot the system but it was impossible to open anything after it finished as it was saying all elements were marked for deletion so I needed to reboot. Also I had to retry 3 times as in this scan the AVG was not willing to deactiivate and crashed twice, also a certain media player crashed before the scan, just in case anything is reflected in the logs. The TDSSKiller log is not new, just from a couple of days ago if you need new one just let me know.
Hello again

P2P - I see you have various P2P programs installed on your machine.

We are not here to pass judgment on file-sharing as a concept but we will warn you that engaging in this activity will always make your computer very susceptible to infection and re-infection. As your computer is infected, it almost certainly contributed to your current situation.

If your computer is infected, it almost certainly contributed to your current situation.

Please note: Even if you are using a "safe" P2P program, it is only the program that is safe. You will be sharing files from uncertified sources, and these are more often than not, infected. Those who write malware use P2P file-sharing as a major vehicle to spread their wares.

Please see this topic for more information:

Perils of P2P File Sharing.

I would strongly recommend that you uninstall them now. You can do so via Control Panel, Programs, and then Programs and Features.

Should you decide to keep them, please don’t use them until we have finished up here.

===================================================

Disable Spybot’s TeaTimer

Spybot’s TeaTimer can sometimes prevent some things from being fixed.

Please disable TeaTimer for now until you are clean. TeaTimer can be re-activated once your log is clean.
  • open Spybot Search & Destroy
  • in the Mode menu click "Advanced mode" if not already selected
  • choose "Yes" at the Warning prompt
  • expand the "Tools" menu
  • click "Resident"
  • uncheck the "Resident "TeaTimer" (Protection of overall system settings) active." box
  • in the File menu click "Exit" to exit Spybot Search & Destroy.
===================================================

Open ComboFix

Please do the following:
  • close any open browsers.
  • close/disable all anti virus and anti malware programs so that they do not interfere with the running of ComboFix.
  • open notepad and copy/paste the text in the codebox below into it:
File::
c:\windows\system32\drivers\SET73BC.tmp

FileLook::
c:\windows\system32\drivers\65054652.sys
c:\windows\system32\services.exe

Save this as "CFScript.txt", and as Type: All Files (*.*) in the same location as ComboFix.exe

[external image: Posted Image]

Referring to the picture above, drag CFScript into ComboFix.exe

When finished, it produces a log at C:\ComboFix.txt. Post the contents of Combofix.txt in your next reply.

================================================

Run Security Check

Download Security Check by screen317 from here or here.
  • save it to your Desktop.
  • double click SecurityCheck.exe and follow the onscreen instructions inside of the black box.
  • a Notepad document should open automatically called checkup.txt; please post the contents of that document.
Please copy and paste the logs in your post, not attach them.

Thanks

Satchfan
Hi Satchfan, thanks for your advice regarding P2P, I know it can be dangerous and I never download ilegal or unsafe content, and if by any chance I get unexpected filetype or size (exe instead of pdf chm etc) I never run them and inmediatly delete them. I have run the two scans as you suggested and here are the logs, however as I feel it could take you a lot of time and effort in cleaning the whole machine, today I bought Kaspersky Internet Security 2013, I haven't installed yet awaiting your advice regarding this, and I hope we manage to make this faster and easier for you this way, as said I won't install as probably it will break part of your plan or something, well, I hope this way its better for you =).
Please don’t install Kaspersky yet. Installing and running it does not cure all malware problems. Although Kaspersky is probably, (IMHO), the best AV around, it cannot detect everything - there isn;t one around that can.

I would suggest however that you uninstall Ad-Aware as the professional version has Ad-Watch which is an antivirus and means that you have 2 currently working against each other. Ad_Aware is also less effective than the one I’m going to ask you to run now.

Download and run AdwCleaner

Download AdwCleaner from here and save it to your desktop.
  • run AdwCleaner and select Delete
  • when it has finished it will ask to reboot - allow the reboot
  • on reboot a log will be produced; please attach the content of the log to your next reply
================================================

Please also run RogueKiller again and send a new log.

Can you tell me the current position with your computer.

BTW, you are still attaching the results of logs instead of copying/pasting them. Please don’t attach these logs.

Thanks

Satchfan
Hi, I'm sorry I haven't run the AdwCleaner yet, I have been having troubles connecting to the internet, the computer very easily get disconnected and unable to reconnect not even after reboot, for some reason, I'm not saying this is due to the fixes you have recommended, perhaps its a side effect of removing certain menace from the system (so if I don't reply in a day or two its maybe due to that) Also I'm sorry I have attached the files instead of copying-pasting the content, I thought that this way it uses less space rather than making 4 consecutive posts or so to include the whole logs content, I will do as you say next time. Additionally I got a trouble getting the AdwCleaner as AVG keeps on saying it has a potential risk and clasify it as trojan menace. is this normal?

I'm sorry I haven't run the AdwCleaner yet, I have been having troubles connecting to the internet,

ComboFix disconnects the Internet temporarily but should have restarted it. Try this

Check that your DHCP Service is running:
  • click on Start
  • type services.msc in the start search bar then press Enter
  • locate the "DHCP Client" line and make sure its status is Started and “Startup Type” is Automatic
.If there is still no connection we will try to fix that later.

I got a trouble getting the AdwCleaner as AVG keeps on saying it has a potential risk and clasify it as trojan menace. is this normal?

Yes. Either disable AVG while you run it or run AdwCleaner and ignore the message.

I'm sorry I have attached the files instead of copying-pasting the content, I thought that this way it uses less space

Thanks for the thouhjt but it is easier for us if you just copy/paste.

I'll wait to hear from you. Can you also tell me the current situation apart from the Internet problem.

Thanks

Satchfan
Hello Satchfan, The current status of the machine is better, I think, can't say if its perfect or not as of course it won't run as fast as first day or reboot as fast with all the programs that load on startup. One fact that clearly was improved is that I no longer hear the computer noise as if it was handling a heavy program with almost no windows open so I think if its not fixed its almost done =). The AdwCleaner was closed as we lost the power in the middle but it seems it managed to generate a report then after that i re-run the process and it finished well this time, so I have two reports from that. Also I'm sorry, I noticed the reports have parts in spanish, but I'm sure you know the reports sections quite well, so I hope its not a trouble and if you need anything about it just tell me. Also one fact that happeend is that I had the Ask & Record bar installed in Firefox and as you will see in the reports it was uninstalled, I wonder if that was potentially risky, because this one has a tool for web audio recording that I need for my job… of course I think there should be a replacement but just wondering if I can go back to it or better avoid that. One last thing is that, as you surely know, on the process end it suggests to enable the PUP and LIP detection on the antivirus program, I haven't done that on AVG as I'm uninstalling it after all is done or when you suggest that, so I think I will do that in Kaspersky instead, I hope its correct that way, but also AdwCleaner suggests that pressing the "?" on the main screen it will install hosts to handle that, is that needed? Here is the first report, interrupted but managed to create the log:AdwCleaner[S1].txt # AdwCleaner v2.009 - Fichero creado el 29/11/2012 a 20:44:53 # Actualizado el 24/11/2012 por Xplode # Sistema operativo : Windows Vista ™ Home Premium (32 bits) # Usuario : ASD-MASTER - ASD # Modo de inicio : Normal # Ejecutado desde : C:\d\adwcleaner.exe # Opción [Supresión] ***** [Servicios] ***** ***** [Ficheros / Carpetas] ***** Carpeta Suprimido : C:\Program Files\AskBarDis Carpeta Suprimido : C:\Program Files\AVG Secure Search Carpeta Suprimido : C:\Program Files\Common Files\AVG Secure Search Carpeta Suprimido : C:\Program Files\Viewpoint Carpeta Suprimido : C:\ProgramData\AVG Secure Search Carpeta Suprimido : C:\ProgramData\Trymedia Carpeta Suprimido : C:\ProgramData\Viewpoint Carpeta Suprimido : C:\Users\ASD-MASTER\AppData\Local\AVG Secure Search Carpeta Suprimido : C:\Users\ASD-MASTER\AppData\LocalLow\AVG Secure Search Carpeta Suprimido : C:\Users\ASD-MASTER\AppData\Roaming\Mozilla\Firefox\Profiles\u4qruwye.default\extensions\{E9A1DEE0-C623-4439-8932-001E7D17607D} Fichero Suprimido : C:\Program Files\Mozilla Firefox\.autoreg Fichero Suprimido : C:\Program Files\Mozilla Firefox\searchplugins\avg-secure-search.xml ***** [Registro] ***** Clave Supprimida : HKCU\Software\APN PIP Clave Supprimida : HKCU\Software\AppDataLow\AskBarDis Clave Supprimida : HKCU\Software\Ask&Record Clave Supprimida : HKCU\Software\AVG Secure Search Clave Supprimida : HKCU\Software\Headlight Clave Supprimida : HKCU\Software\IGearSettings Clave Supprimida : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Ask Toolbar_is1 Clave Supprimida : HKCU\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\ViewpointMediaPlayer Clave Supprimida : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{201F27D4-3704-41D6-89C1-AA35E39143ED} Clave Supprimida : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{0702A2B6-13AA-4090-9E01-BCDC85DD933F} Clave Supprimida : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{201F27D4-3704-41D6-89C1-AA35E39143ED} Clave Supprimida : HKLM\Software\AVG Secure Search Clave Supprimida : HKLM\SOFTWARE\Classes\AppID\{1FDFF5A2-7BB1-48E1-8081-7236812B12B2} Clave Supprimida : HKLM\SOFTWARE\Classes\AppID\ScriptHelper.EXE Clave Supprimida : HKLM\SOFTWARE\Classes\AppID\ViProtocol.DLL Clave Supprimida : HKLM\SOFTWARE\Classes\AVG Secure Search.BrowserWndAPI Clave Supprimida : HKLM\SOFTWARE\Classes\AVG Secure Search.BrowserWndAPI.1 Clave Supprimida : HKLM\SOFTWARE\Classes\AVG Secure Search.PugiObj Clave Supprimida : HKLM\SOFTWARE\Classes\AVG Secure Search.PugiObj.1 Clave Supprimida : HKLM\SOFTWARE\Classes\AxMetaStream.MetaStreamCtl Clave Supprimida : HKLM\SOFTWARE\Classes\AxMetaStream.MetaStreamCtl.1 Clave Supprimida : HKLM\SOFTWARE\Classes\AxMetaStream.MetaStreamCtlSecondary Clave Supprimida : HKLM\SOFTWARE\Classes\AxMetaStream.MetaStreamCtlSecondary.1 Clave Supprimida : HKLM\SOFTWARE\Classes\CLSID\{03F998B2-0E00-11D3-A498-00104B6EB52E} Clave Supprimida : HKLM\SOFTWARE\Classes\CLSID\{0702A2B6-13AA-4090-9E01-BCDC85DD933F} Clave Supprimida : HKLM\SOFTWARE\Classes\CLSID\{08993A7C-E764-4172-9627-BFB5EA6897B2} Clave Supprimida : HKLM\SOFTWARE\Classes\CLSID\{128A6C66-AC6A-4617-8268-AB7F47B7215E} Clave Supprimida : HKLM\SOFTWARE\Classes\CLSID\{1B00725B-C455-4DE6-BFB6-AD540AD427CD} Clave Supprimida : HKLM\SOFTWARE\Classes\CLSID\{201F27D4-3704-41D6-89C1-AA35E39143ED} Clave Supprimida : HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217} Clave Supprimida : HKLM\SOFTWARE\Classes\PROTOCOLS\Handler\viprotocol Clave Supprimida : HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi Clave Supprimida : HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi.1 Clave Supprimida : HKLM\SOFTWARE\Classes\ViProtocol.ViProtocolOLE Clave Supprimida : HKLM\SOFTWARE\Classes\ViProtocol.ViProtocolOLE.1 Clave Supprimida : HKLM\Software\Headlight Clave Supprimida : HKLM\Software\MetaStream Clave Supprimida : HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\{03F998B2-0E00-11D3-A498-00104B6EB52E} Clave Supprimida : HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\{1B00725B-C455-4DE6-BFB6-AD540AD427CD} Clave Supprimida : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{201F27D4-3704-41D6-89C1-AA35E39143ED} Clave Supprimida : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Ask Toolbar_is1 Clave Supprimida : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ViewpointMediaPlayer Clave Supprimida : HKLM\SOFTWARE\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin Clave Supprimida : HKLM\SOFTWARE\MozillaPlugins\@viewpoint.com/VMP Clave Supprimida : HKLM\Software\PIP Clave Supprimida : HKLM\Software\Viewpoint ***** [Navegadores] ***** -\\ Internet Explorer v7.0.6000.16757 [OK] El registro no contiene ninguna entrada ilegítima. -\\ Mozilla Firefox v3.0.8 (es-ES) Nombre del perfil : default Fichero : C:\Users\ASD-MASTER\AppData\Roaming\Mozilla\Firefox\Profiles\u4qruwye.default\prefs.js Supprimida : user_pref("SothinkWebVideoDownloaderWebVideoDownloader.DownloadedArray_1516.url", "http://veoh-097.v[…] Supprimida : user_pref("SothinkWebVideoDownloaderWebVideoDownloader.DownloadedArray_1557.url", "http://veoh-106.v[…] Second report, this one finished succesfully and took some time to complete:AdwCleaner[S2].txt # AdwCleaner v2.009 - Fichero creado el 29/11/2012 a 21:20:40 # Actualizado el 24/11/2012 por Xplode # Sistema operativo : Windows Vista ™ Home Premium (32 bits) # Usuario : ASD-MASTER - ASD # Modo de inicio : Normal # Ejecutado desde : C:\d\adwcleaner.exe # Opción [Supresión] ***** [Servicios] ***** ***** [Ficheros / Carpetas] ***** ***** [Registro] ***** ***** [Navegadores] ***** -\\ Internet Explorer v7.0.6000.16757 [OK] El registro no contiene ninguna entrada ilegítima. -\\ Mozilla Firefox v3.0.8 (es-ES) Nombre del perfil : default Fichero : C:\Users\ASD-MASTER\AppData\Roaming\Mozilla\Firefox\Profiles\u4qruwye.default\prefs.js Supprimida : user_pref("SothinkWebVideoDownloaderWebVideoDownloader.DownloadedArray_1516.url", "hxxp://veoh-097.v[…] Supprimida : user_pref("SothinkWebVideoDownloaderWebVideoDownloader.DownloadedArray_1557.url", "hxxp://veoh-106.v[…] Supprimida : user_pref("extensions.snipit.askTbInstalled", true); -\\ Opera v11.62.1347.0 Fichero : C:\Users\ASD-MASTER\AppData\Roaming\Opera\Opera\operaprefs.ini [OK] El fichero no contiene ninguna entrada ilegítima. ************************* AdwCleaner[S1].txt - [5351 octets] - [29/11/2012 20:44:53] AdwCleaner[S2].txt - [1245 octets] - [29/11/2012 21:20:40] ########## EOF - C:\AdwCleaner[S2].txt - [1305 octets] ##########

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI