Windows 7 problems. Logs attached. Please help.

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by delslp, Sep 8, 2011.

  1. delslp

    delslp Private E-2

    Computer is only 4 months old. Began having issues approximately 2 months ago. Slow startup, will get Windows splash screen then screen goes black and white cursor is visible. Sometimes takes up to 20 minutes for desktop to finally show up. Problems with programs (particularly Office programs) not responding. HDD light blinks incessantly during black screen and while programs are not responding. Frequently cannot access control panel items. Will get "not responding" msg and/or green progress bar will move at a snails pace. HDD has been defragmented.
    Anti-virus program real time protection will disable and I am not able to re-enable. (Had this issue with 2 different anti-virus programs) Then several reboots later anti-virus program protection will start again.

    Ran programs per Read Me section in this forum. Unable to run MGtools. DOS looking window comes up and system info runs, then it simply closes both the DOS looking window (for lack of a better term) and the system info window. No logs are in the MGtools folder. Antivirus disabled and UAC off during this process. I have a screen capture of MGtools DOS screen if you need it.

    Have contacted laptop manufacturer and their suggestion was to completely wipe hard drive. Ugh!
    I really appreciate the help.
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I want you to run TDSSKiller so refer to the below for how to do so.

    TDSSkiller - How to run

    Please also download MBRCheck to your desktop
    • Double click MBRCheck.exe to run (vista and Win 7 right click and select Run as Administrator)
    • It will show a Black screen with some information that will contain either the below line if no problem is found:
      • Done! Press ENTER to exit...
    • Or you will see more information like below if a problem is found:
      • Found non-standard or infected MBR.
      • Enter 'Y' and hit ENTER for more options, or 'N' to exit:
    • Either way, just choose to exit the program at this point since we want to see only the scan results to begin with.
    • MBRCheck will create a log named similar to MBRCheck_07.16.10_00.32.33.txt which is random based on date and time.
    • Attach this log to your next message. (See: HOW TO: Attach Items To Your Post )


    Download OTL to your desktop.

    • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
    • Vista and Windows 7 users Right-click OTL and choose Run as Administrator)
    • When the window appears, underneath Output at the top change it to Minimal Output.
    • Check the boxes beside LOP Check and Purity Check.
    • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.

    When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.

    Attach both of these logs into your next reply.
     
  3. delslp

    delslp Private E-2

    Thanks for your quick reply. Requested logs attached.
     

    Attached Files:

  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Are you set up to use a proxy?
     
  5. delslp

    delslp Private E-2

    To my knowledge I am not set up to use a proxy server (at least not on purpose!)
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please try it again now. There was a problem with the last file. I just updated it. Download and run the new MGtools See if it makes the MGlogs.zip file now. Thanks!
     
  7. delslp

    delslp Private E-2

    worked beautifully this time. ;)
     

    Attached Files:

  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    If you did not deliberately set this proxy yourself then please include it in the HJT fix below:


    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 192.168.0.1:84
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 192.168.0.1;<local>;*.local

    After clicking Fix exit HJT.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista or Windows7) Then attach the new C:\MGlogs.zip file that will be created by running this.

    Let me know of any problems you may have encountered with the above instructions and also let me know how things are running now!
     
  9. delslp

    delslp Private E-2

    log file attached. After making the requested changes I restarted my computer. System has been starting up quickly about 90% of the time. However, it is still acting strangely. For instance, after this last restart, going to the start menu ->programs opened a blank list. Anti-virus would not turn back on stating that it has timed out. Attempts to go to control panel resulted in a blank screen opening that did not populate even after 10 minutes had passed. HDD light blinking the whole time. Restarted again and everything came up and worked fine.
    Thank you again for your help!
     
  10. delslp

    delslp Private E-2

    status update:
    had to restart computer again and this time internet connection was not available (could not even get into control panel to try to fix), control panel screen would not populate, anti-virus software was off and could not be started, HDD light flashing incessantly. Restarted in safe mode with networking and received msg that start up had errors and it stated startup repair needed to be run. Startup repair ran and requested use of restore point, then it automatically restarted computer. Booted up quickly, but every program I tried to open would go to a screen that would not populate or would say "not responding", anti-virus not active and could not get it to start. No anti-virus protection, no internet access. Restarted again in safe mode: network connection resumed and programs that previously would not open worked just fine.
     
  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You didn't attach the file. This is starting to sound more and more like a system problem rather than malware issue.
     
  12. delslp

    delslp Private E-2

    I went through the motions on my post before last. I then tried to attach it again and realized it gave a small error msg at the top of the box saying the file had already been attached to a previous post. So, I renamed it and attempted to attach it to this post, but I get the same error even with the name changed. I would assume it would automatically overwrite the old log with the new. Do I need to do something differently?
    Thanks.
     

    Attached Files:

  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You cannot attach the same log as you previously attached no matter what name you call it. You need to follow the instructions Kestrel13! gave you to create a new log:
     
  14. delslp

    delslp Private E-2

    Thanks chaslang. I had run the scan and thought it generated a new file. Will try this again. :)
     

    Attached Files:

  15. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I am not finding any malware in your logs. However, let me suggest a few things:

    I strongly advise you to cleanup your Desktop. Remove everything but links to run programs. Do not download and save programs here and definitely do not use it for long term storage. A cluttered Desktop is malware's playground and it can also cause performance degradation especially when you start saving large files here like you are doing.

    I also suggest that you use CCleaner and clean out this folder:
    C:\Users\Denise\Local Settings\TEMP

    Then use windows explorer and delete this file:
    C:\windows\tasks\09-06-2011_190244.job

    I will lastly suggest that you post in the software forum, as this would appear to be a system issue.

    Since you are not having any malware problems, it is time to do our final steps:

    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.We recommend them for doing backup scans when you suspect a malware infection.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.

    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:


    Malware removal from a National Chain = $149
    Malware removal from MajorGeeks = $0


    Majorgeeks Geek Wear. Hats, T-Shirts, Hoodies

    MajorGeeks on FaceBook
     
  16. delslp

    delslp Private E-2

    MUCH thanks!
     
  17. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are most welcome. Safe surfing. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds