EXTREMELY SLOW and BSOD

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by soph4, May 31, 2011.

  1. soph4

    soph4 Private E-2

    I have an inherited Dell that consistently crashes (BSOD) on start up. If it does start up it takes 15 minutes and then 5 minutes to switch between programs.

    I have run through the READ Me series, but with troubles.

    Initially the SUperAntispyware and amlwarebytes both crashed the system.

    I moved on to the rest of the series and got the logs.

    I then tried Superantispyware again and did get a log...

    and I finally got Malwarebytes to run - but in safe mode.

    Attached are the logs in sequence.

    Thanks for the help
     

    Attached Files:

  2. soph4

    soph4 Private E-2

    Lat log attached
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I am not finding any malware in your logs. However, one of your system files is corrupt. Let's do this:

    * Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    If it is not on your Desktop, the below will not work.
    * Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    * If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    * Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    KILLALL::
    
    FCopy::
    C:\WINDOWS\SoftwareDistribution\Download\e9500597a78495f397efb821e37bf356\atapi.sys | c:\windows\system32\Drivers\atapi.sys
    
    Quit::
    
    * Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    * At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    * You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    If it asks you to overide the previous file with the same name, click YES.
    * Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif
    * Follow the prompts.
    * When it finishes, a log will be produced named c:\combofix.txt
    * I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Please attach the new Combo log:
    C:\ComboFix.txt
     
  4. soph4

    soph4 Private E-2

    I have tries twice now to run this but the computer crashes (BSOD) after stage 48 or so. It has taken an hour both time before finally crashing.

    I did try to boot in safe mode - but combofix.exe doesn't appear on the desktop. Any suggestions?

    Thanks
     
  5. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Download a FRESH version of combofix but do not run it yet!

    Please do the following:

    1. Click on the Start button, then click on Run...

    2. In the empty "Open:" box provided, type cmd and press Enter

    * This will launch a Command Prompt window (looks like DOS).

    3. Copy the entire bold text below to the clipboard by highlighting all of it and pressing Ctrl+C (or after highlighting, right-click and select Copy).

    4. In the Command Prompt window, paste the copied text by right-clicking and selecting Paste.

    5. Press Enter.

    6. When successful, you should get the below message within the Command Prompt:

    * "1 file(s) copied"

    7. NOTE: If you didn't get this message, stop and tell me first. Executing any following instructions (with avenger) are dependent upon this file being successfully copied.

    8. Exit the Command Prompt window.

    9. Now download The Avenger by Swandog469, and save it to your Desktop.

    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Now run the new copy of Combofix from your desktop.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista or Windows7) Then attach the new C:\MGlogs.zip file that will be created by running this.

    Let me know of any problems you may have encountered with the above instructions and also let us know how things are running now!
     
  6. soph4

    soph4 Private E-2

    OK, I ran Avenger as suggested (log attached), but Combofix still crashed. It had finished the stages (50) and had begun deleting something when it froze and ultimately blue screened. This took over an hour.

    Thanks again
     

    Attached Files:

  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

  8. soph4

    soph4 Private E-2

    OK, I ran TDSSKiller (Log attached). I see no improvements. The computer still takes 15 minutes to boot and now everything on the screen is MASSIVE!

    I did tell TDSSKiller to "delete" all suspicious items. It might have been too much...I have a 17" monitor but this window doesn't completely fit, each font letter is about half an inch high. HELP! :)
     

    Attached Files:

  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Right click your desktop and choose properties. Go to your display settings and see if you can't adjust the screen size.
     
  10. soph4

    soph4 Private E-2

    OK, that part is back to normal, but the thing is still painfully slow. It is still taking 15 minutes to boot and once started is slow to react to any command...

    Thanks
     
  11. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    See what Chaslang said in the fighter forum, Tim. :) I am not going to get chance to do this this weekend, but TDSSKiller obviously attacked things it should not have.
     
  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Tell me if this folder exists and if it does, do you have the ability to unquarantine what is in it:
    C:\TDSSKiller_Quarantine

    If it doesn't have anything in it, you can also try doing a system restore to a point before you ran TDSSKiller.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds