Computer Runs Very Slowly

Discussion in 'Malware Help (A Specialist Will Reply)' started by rharris, May 2, 2008.

  1. rharris

    rharris Private E-2

    Hi. My computer started to run very slowly. This happen suddenly. Symptoms include extended boot-up period (20 minutes) and very slow uploads along with frequent "program not responding" errors.

    At the same time, my Outlook Express was disabled so that I can not reply to incoming e-mails and my address book was erased. My McAfee (paid subscription) was deleted and when I try to reload it, it will not work. I can not do any on-line updates on AVG and my Ad-aware was also erased and I can not reload it. Additionally, PDF files can not be opened and I tried to reload Adobe from the website and it will not work.
    I tried another (obviously inferior) support forum and they gave up on me. I have run all of the things that were suggested in the "readme" files and hopefully posted the logs correctly. SuperAntiSpyware did not find anything when I ran it this morning so I guess there is no log for that one.

    I have been struggling with this for a couple of months and I hope you can help. Thank you in advance for your time and the website.
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are not having a malware problem ...I suspect that the slowness is caused by having too many anti-virus programs installed:
    C:\Documents and Settings\All Users\Application Data\Avira
    C:\Program Files\Panda Security
    McAfee SecurityCenter

    You may wish to use a Startup Manager

    And you can uninstall all of your old Java versions.

    However you may wish to post in the software section for further advice. :)
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Only McAfee is currently installed Tim! However a service for Kaspersky is running.

    O23 - Service: setup_7.0.0.180_14.04.2008_03-40[1] - Kaspersky Lab - C:\Documents and Settings\All Users\Desktop\Kaspersky Lab Tool\setup_7.0.0.180_14.04.2008_03-40[1].exe
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Thanks Chas.....

    @rharris...you should also uninstall Viewpoint Manager. It would be best to Uninstall all previous versions of Java ...then reboot and install:
    Java Runtime 6

    Then Run thisDisable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Uninstall SUPERAntispyware now too since it is no longer needed.

    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    All of this may help you to run a little faster. :)
     
  5. rharris

    rharris Private E-2

    Hi. Thank you for the suggestions. I did all of the items you said to do and there does not appear to be any improvement in the performance of the computer.
    Is there anything else you can suggest and other logs to post for your review?

    The problems with the e-mail and pdfs (not being able to download adobe) are not addressed. Also, I can not back up files as the cd drive is not recognized.

    I assume, based on the suddeness (if that is a word) of the problem, that there must be some virus or something that has disabled all of this stuff.

    I am getting desperate. Thanks again.

    Rharris
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    As previously stated....this is not a malware issue and I would suggest that you post in the software section. You may need to do a repair install or try going back to a restore point before this occurred.

    However...please first run the McAfee Removal Tool and then please run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.
     
    Last edited: May 6, 2008
  7. rharris

    rharris Private E-2

    I did what you asked. The McAfee did not complete its run. I attached that log, too.

    The first thing I tried when this started was a restore but it did not work. I am worried about reloading the operating system without being able to back up stuff, though.

    Thanks for your help. Rharris
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Let's see if we can manually remove McAfee. First just go to Add/Remove Programs and try uninstalling McAfee SecurityCenter. No matter what happens, just continue on with all of the below. If the uninstall works, some of the items you see further down may no exist anymore. Just ignore and continue.


    Some of the below steps will also remove a few files from your Desktop that should not be saved there.

    First let's remove a couple of services:
    • Click on Start, then Run ... type services.msc into the box that opens up, and press 'OK'.
    • On the page that opens, scroll down to setup_7.0.0.180_14.04.2008_03-40[1]
    • then right click the entry, select Properties and press Stop Service.
    • When it shows that it is stopped, next please set the Start-up Type to 'Disabled'.
    • Now repeat the above for SiteAdvisor Service
    • Click OK until you get back to Windows.
    Uninstall the below old versions of software:
    J2SE Runtime Environment 5.0 Update 11
    J2SE Runtime Environment 5.0 Update 8
    Java(TM) SE Runtime Environment 6 Update 1

    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: (no name) - {089FD14D-132B-48FC-8861-0048AE113215} - C:\Program Files\SiteAdvisor\6253\SiteAdv.dll
    O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\PROGRA~1\mcafee\VIRUSS~1\scriptsn.dll
    O3 - Toolbar: McAfee SiteAdvisor - {0BF43445-2F28-4351-9252-17FE6E806AA0} - C:\Program Files\SiteAdvisor\6253\SiteAdv.dll
    O4 - HKLM\..\Run: [mcagent_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
    O4 - HKLM\..\Run: [SiteAdvisor] "C:\Program Files\SiteAdvisor\6253\SiteAdv.exe"
    O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe"
    O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScan Control) - http://download.ewido.net/ewidoOnlineScan.cab
    O16 - DPF: {C02226EB-A5D7-4B1F-BD7E-635E46C2288D} (Toontown Installer ActiveX Control) - http://a.download.toontown.com/sv1.0.18.39/ttinst.cab

    After clicking Fix, exit HJT.



    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.

    No just to be safe, try running the McAfee Removal Tool again and then no matter what happens continue on with the below.

    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it.


    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  9. rharris

    rharris Private E-2

    Thank you for the help. Things seem a little better now. The operation is quicker.
    I removed McAfee Security Center first. This also removed some of the things on the HJT analysis.

    I can't get rid of those Java things. I got three error messages:
    int. error 3212 c:\program files\java\jei.5.0_11\lib\ext\sunpacs11.jac
    int error 2318 c:\program files\java\ire 1.6.0_01\lib\21\australia\brisbane
    int. error c:\program files\jave\jre 1.5.0.08\lib\21\europe\berline
    and then it said "fatal error" on each one.

    I did the Combofix and regedit and they both worked fine. I ran CCcleaner and the mgtools and have attached the requested logs.

    I assume that my problems with e-mail, etc. are software related?
     

    Attached Files:

  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    See if you can use the below program to uninstall them:

    Your Uninstaller! 2008

    What is the exact problem?
     
  11. rharris

    rharris Private E-2

    Thank you. That uninstaller is working well!

    At the same time the problems started, I had a number of issues come up. I can not reply to e-mails, my address book was erased and I can not open PDF files. I tried to reinstall Adobe but it would not complete.
    Also, I can not back up files on CD. Other functions such as system restore do not work correctly, either.
    Thanks for the help.
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    These are all topics for the Software Forum. Note if you did not have a backup of your address book it is more than likely lost.

    If you are not having malware problems, it is time to do our final steps which will also get you properly protected again since you have no protection currently:
    1. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop & renamed it like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\cf" /u
        • Notes: The space between the cf" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\cf folder from combofix.
    2. If we had you run Avenger, you can delete all files related to Avenger now.
    3. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    4. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    7. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds