Severly slow w/a chance of Hard Freeze

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by JustKate, Dec 11, 2009.

  1. JustKate

    JustKate Private E-2

    I don't know if this is where I belong, but I trust someone will put me in my place if it's not. ;)

    I'm working on an HP Pavillion, AMD Athlon XP 2800+ 2.08 GHz 1.18 GB of RAM (which is all geek to me :-o). Running Microsoft Windows XP Home Edition Version 2002 Service Pack 3.

    My daughter was using my computer, don't know what doing, but I got hit with a hard freeze the next time I booted it up. I had to hold in the on/off button to re-start it, nothing moved. When I booted it back up, everything moved at a snail pace. Even my start up time is far slower than before. I haven't regained any speed. I've had several more hard freezes since. It's been going on about a week or ten days.

    I have done Read & Run me first, and the Windows XP Cleaning Procedure. I am attaching my logs in hopes that someone can find something that the tools didn't. I did have the Ask toolbar on my add/delete programs, and was unable to un-install it.

    I hope I got the attachments right, I'm not too knowledgeable about these things, but I try. Also, I have two Malwarebytes logs, one apparently ran while I was at work, hmmm.

    Thanks for your assistance during this busy time of year!
     

    Attached Files:

  2. JustKate

    JustKate Private E-2

    The remaining logs ...
     

    Attached Files:

  3. JustKate

    JustKate Private E-2

    and Combofix .. I think I have too much stuff on my puter rolleyes .. oh oh, the Combofix file is 262.4 KB, which is too big to attach, any suggestions?
     
  4. JustKate

    JustKate Private E-2

    I split the Combofix file into two files, hopefully this will work .. thanks!
     

    Attached Files:

  5. JustKate

    JustKate Private E-2

    And here's ComboFixB.txt .. part 2 .. sorry :-o

    Thanks again!
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Please explain what operations are slow! For example answer the below:
    • Is boot up slow?
    • Is shutdown slow?
    • Is browsing/surfing slow?
    • Is downloading slow?
    • Is running any application?
    • Is it also slow in safe boot mode?
    • Also are any process showing in Task Manager to be using a lot of CPU time?
    • Anything else slow?
    Your logs did not show any major malware and mostly just a lot of unnecessary junk was removed including some non-recommended games that may be what your daughter installed.
     
    Last edited: Dec 12, 2009
  7. JustKate

    JustKate Private E-2

    My boot up time is slower than normal, but browsing is very slow. I'm still getting the hard freeze. The screen looks like is has a rainbow of opaque pixels over it when it freezes, and my mouse and keyboard both stop responding. The freeze comes both when I'm sitting idle and when I'm actively browsing.

    The task manager doesn't show any change when it freezes. I've pulled it up to see if something might indicate a freeze coming on. It seems that my biggest user is the system idle process, which is normally sitting on 98-99 percent, even when I'm trying to open a window.

    When I'm running apps, the CPU occassionally goes to 100 and hangs there until I close the window I'm working in. Downloads seem to be pretty normal, and shutting down doesn't seem to be slowed much.

    I appreciate you looking at my logs and hope this information is what you need to know, but if you need more I'll do my best to explain. Thanks Again!
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This is not a process. This is a measure of the idle time of your PC which means it is doing nothing 98 to 99 % at that instance of time.

    You did not address my question about whether you have problems in safe boot mode. Right now it looks like your problems are not due to malware. I will give you a few things to do below which are not malware. We will be testing to see if anything changes after uninstalling various programs and tweaking a few other items.


    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R3 - URLSearchHook: (no name) - *{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (file missing)
    O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - (no file)
    O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
    O16 - DPF: {DBA230D1-8467-4e69-987E-5FAE815A3B45} -
    O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} -
    O18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - (no file)
    O23 - Service: McAfee Application Installer Cleanup (0140151223865158) (0140151223865158mcinstcleanup) - Unknown owner - C:\DOCUME~1\Owner\LOCALS~1\Temp\0140151223865158mcinst.exe (file missing)

    After clicking Fix, exit HJT.


    Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Do you use MusicMatch Jukebox? If not then add it to the list of things to uninstall below since it is a waste of resources having it always running.

    Uninstall ALL of the below and reboot afterwards. If any of them tell you to reboot to complete the uninstall, then reboot immediately and continue on after the reboot.
    a-squared Free 4.0
    Advanced SystemCare 3
    Ask Toolbar
    AVG Free 9.0
    Smart Defrag 1.20


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).



    Then attach the below log:
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
    Last edited: Dec 14, 2009
  9. JustKate

    JustKate Private E-2

    chaslang,

    Thank you for you help. I ran into some problems with your instructions, but did the best I could. I ran the C:\MGtools\analyse.exe from the run prompt. I think I might not have MGtools installed correctly. When I click on the icon, it runs in a C:\ window. The 04 - HKCU items you asked me to delete were already gone, and the 023 Service: McAfee Application Installer Cleanup wouldn't leave.

    I removed Windows Messenger successfully.

    I, also deleted MusicMatch Jukebox, as I don't use it, and Advanced SystemCare3, AVG Free 9.0, and Smart Defrag 1.20.

    When trying to remove the Ask Toolbar, I got the following error, "File C:\ProgramFiles\AskBarDis\unins 000 dat" does not exist. Cannot uninstall.

    a-squared Free 4.0 I received the following error, messages file "C"\ProgramFiles\a-squaredFree\unins 000msg" is missing. Please correct the problem or obtain a new copy of the program.

    I did reboot after the uninstalls, and ran C:\MGtools\GetLogs.bat from the run prompt. I am attaching the C:\MGlogs.zip.

    When I booted back up and tried to sign in to attach the zip log last evening, I got locked up with the hard freeze again.

    Also, I was able to boot up in safe boot mode, but nothing unusual happened while I was there.

    I am without virus protection at the moment since I have uninstalled AVG Free 9.0. Is there another free virus program you might recommend?

    Thanks again for you help, I know you are busy. Your kindness is appreciated.

    Kate
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    We will manually remove anything that remains.

    Let's reinstall and then uninstall. Download and install the below.

    a-squared Free edition

    Then uninstall it.

    If you don't get any freeze ups in safe mode then it is likely that some program or driver that loads in normal boot mode but not in safe mode could be causing your problem.

    First we need to finish removing a few items to see if we can locate the cause of your freezing. It may be necessary for you to work this in the Software Forum though since as I said, it is most likely not malware related.

    Now run Glary Utilities that you have installed and undo any settings you have made to disable various startups.

    Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O3 - Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
    O16 - DPF: {BB21F850-63F4-4EC9-BF9D-565BD30C9AE9} (a-squared Scanner) - http://ax.emsisoft.com/asquared.cab

    After clicking Fix, exit HJT.

    Now we are going to try the beta version of ComboFix which is named KittyFix.exe

    Download KittyFix from http://download.bleepingcomputer.com/sUBs/Beta/KittyFix.exe and save it to your Desktop but do not run it.

    Note: This is a beta version of combofix and might be unstable but tests done so far have proved it works well

    Note: It is important that it is saved directly to your desktop and run from the desktop and not any other folder on your computer.
    • Now Exit/Close/Disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
    • Close any open browsers and any other programs you might have running.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as KittyFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the KittyFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of KittyFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:
    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    Also delete all files and subfolders in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\Temp
    C:\Documents and Settings\Owner\Local Settings\temp

    Now run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.

    Now download the current version of MGtools and save it to your root folder. Overwrite your previous MGtools.exe file with this one.

    Run MGtools.exe ( Note: If using Vista make sure UAC is still disabled. Also don't double click on it, use right click and select Run As Administrator )

    Now attach the below log:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  11. JustKate

    JustKate Private E-2

    Okay!

    Chaslang, I hope I did everything okay to find the information you need. Thanks for being so patient and helpful with me, I'm finding out I don't know how to do a lot of things.

    I encountered a lot of freezing while running the steps you gave me to do, so I booted into safe mode to finish things up. The computer hasn't frozen once since booting into safe mode.

    Start up is still slow, I think there may be things booting up that I am not aware of. Still hard freezing in regular mode. I do notice an improvement on the speed at which the programs are running. Browsing and surfing is still slow tho. I got a new ISP last week and downloads are very fast at the moment.

    Attached please find the logs you asked for. Let me know if I didn't get things right, or what I need to do next. I saved the new MGtools to the C:\MGtools folder. I'm just not real sure that I did that right.

    Thanks again for all your help. I appreciate you very much!

    Kate
     

    Attached Files:

    Last edited: Dec 20, 2009
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Your log from MGtools was obtained in safe boot mode. You need to always get logs from normal boot mode unless we ask you to run in safe boot mode. Since we already know you don't have freeze problems in safe boot mode, but you do in normal boot mode, the problem is just something you are loading in normal mode. It could be a driver for your hardware or a piece of software. Please attach a new log from MGtools from normal boot mode. You may as well download and use the new version again since it just updated again today.
     
  13. JustKate

    JustKate Private E-2

    Chaslang,

    Sorry, I didn't know about the safe mode not being acceptable. I downloaded and ran MGtools again in normal mode.

    I got an error as follows while MGtools was running:
    Application has generated an exception that could not be handled. Process id = 0xb0 (176), Thread id 0xd0c (3340) Hit okay to terminate, cancel to debug.

    I hit cancel, and got the following error:
    Registered JIT debugger not available. Attempt to launch JIT debugger with following command resulted in error code of 0x2 (2). Check computer settings. Cordbg.exe !a0xb0

    I canceled the debugger at this point, and the resulting log is attached.

    Thanks so much for your help. I appreciate you understanding.

    Kate
     

    Attached Files:

  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay we have done more than we should be in this forum. Even what I did in my last message was not related to malware. Your problems are related to what you are loading in normal bootmode and slow internet may just be your ISP or the junk you installed from them. My last suggestions will be below. Anything else you will have to work in the Software Forum or with your ISP for internet speed issues with browsing.


    First I would suggest that you uninstall all of the below from your ISP since the have been notorious to cause people problems.
    • Comcast Access
    • Comcast Desktop Software (v1.2.0.9)
    • Desktop Doctor
    The below services are run due to the above software and everyone I know who has them running has had problems or complained about them:
    C:\Program Files\Common Files\Motive\McciCMService.exe
    C:\Program Files\Comcast\Desktop Doctor\bin\sprtsvc.exe

    Uninstall them reboot, and make sure all of the below are gone from your HijackThis log that you can see by running MGtools and looking at the hijackthis.log in the MGtools folder.


    I also suggest uninstalling Google Toolbar and the service that goes along with it and its ever running autoupdater.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds