laptop freezing have tried everything I know

Discussion in 'Malware Help (A Specialist Will Reply)' started by mastermiaow, Oct 29, 2014.

  1. mastermiaow

    mastermiaow Private First Class

    Dear Major geeks

    I have a compaq mini110 notebook which is about 5 years old. I have used it occasionally and one of my pleasures has been to be able to watch netflix movies when I am on the road. However for the last approx 6 months I have experienced lots of freezing and very slow start up and now it is not possible to watch an online film. When this happens CPU is showing at maximum but RAM seems well within capacity. I am able to watch films from the hardrive with no problem. The processor is 1.6Ghz and I have boosted memory to 1.99gb
    Recently I have purchased IObit advanced system care and run everything including defragmenting, and culling start up programmes.
    I thought the problem might be Chrome using up too much capacity so downloaded Midori, two windows come up one after the other saying cannot start because a libglib.dll file is missing but then it does start up only to often crash :confused

    I have run all the malware although I was unable to download latest cc cleaner version but ran one already installed on laptop
    I could not get mgtools to work after downloading to C folder. Messages were:
    Getlogs.bat Windows cannot access the specific path
    Failed to run Getlogs.bat, working dir =MGtools (check to see if this file is in EXE).
    I am attaching relevant text files from malware scan.

    Many thanks for your help

    Matthew
     

    Attached Files:

  2. mastermiaow

    mastermiaow Private First Class

    I realise that MGtools did create a folder in C drive with lots of files in it but the only file with name of zip is an executable programme. I tried to attach a doc file with print shot but it is exceeds capacity so I am stumped as to how to show you what is in the folder :(
     
  3. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Run MGTools.exe in safe mode then please. :)
     
  4. mastermiaow

    mastermiaow Private First Class

    OK here it is :)
    One other thing is that on starting, I get new hardware found wizard starting and have to cancel it :confused
     

    Attached Files:

  5. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Before we continue I would like for you to use MSConfig to put this machine back into normal start up mode. Any other mode is primarily used for troubleshooting and diagnostic purposes. You should look into some third party software to control start up's.

    Uninstall the below garbage:

    • Viewpoint Media Player



    http://img805.imageshack.us/img805/9659/rktigzy.gif Fix items using RogueKiller.

    Double-click RogueKiller.exe to run. (Vista/7/8 right-click and select Run as Administrator)
    When it opens, press the Scan button
    Now click the Registry tab and locate these detections:

    • [PUP] HKEY_CLASSES_ROOT\CLSID\{03F998B2-0E00-11D3-A498-00104B6EB52E} -> Found
    • [PUP] HKEY_CLASSES_ROOT\CLSID\{1B00725B-C455-4DE6-BFB6-AD540AD427CD} -> Found
    • [PUM.HomePage] HKEY_USERS\S-1-5-21-90005891-1473313898-1233967428-1006\Software\Microsoft\Internet Explorer\Main | Start Page : http://search.conduit.com?SearchSou...=SPBD578B5E-A29B-4370-9DA6-F309B0516452&SSPV= -> Found
    • [PUM.Desktop] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\SystemRestore | DisableSR : 1 -> Found

    Place a checkmark next to each of these items, leave the others unchecked.
    Now press the Delete button.
    When it is finished, there will be a log on your desktop called: RKreport[2].txt
    Attach RKreport[2].txt to your next message. (How to attach)
    Reboot the machine.



    Download and run OTM.

    Download OTM by Old Timer and save it to your Desktop.

    Code:
    :Files
    C:\Documents and Settings\Matthew\Local Settings\Application Data\Conduit
    C:\Documents and Settings\All Users\Application Data\{3C5CBD7B-3D1D-411E-96C2-513FFCA84D2D}
    
    :reg
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{71551D86-27E0-4554-8F8F-777DEE5B39D6}]
    [-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9}]
    [-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{71551D86-27E0-4554-8F8F-777DEE5B39D6}]
    [-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}]
    
    :Commands
    [emptytemp]
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar) and choose Paste.
    • Push the large http://farm3.static.flickr.com/2782/4174320048_f01c448b32_o.png button.
    • OTM may ask to reboot the machine. Please do so if asked.
    • Copy everything in the Results window (under the green bar), and paste it into a text file to ATTACH into your next reply.

    NOTE: If you are unable to copy/paste from this window (as will be the case if the machine was rebooted), open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTM\MovedFiles folder, and open the newest .log file present, and attach the contents of that document back here in your next post.



    http://imageshack.us/a/img841/7292/thisisujrt.gif Please download Junkware Removal Tool to your desktop.
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.

    Run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista, Windows7 or Win8) Then attach the new C:\MGlogs.zip file that will be created by running this.

    Let me know of any problems you may have encountered with the above instructions and also let me know how things are running!
     
  6. mastermiaow

    mastermiaow Private First Class

    Hi Kestrel

    You are a star for all your help and knowledge :)

    I put machine in normal start up and have use IObit start up manager to disable or delete unnecessary programs.
    I ran Roguekiller and deleted the items you described. The two PUP items showed details up to CLSID but not anything more but I assume they were the right ones... There doesn't seem to be a text file on desktop with name of RKreport so I haven't attached
    I had to start in safe mode after using OTM but it worked and I am attaching log.
    I was unable to run JRT.exe with error messageNon 7z archive
    I had to switch back to midori as IE seemed to crash before even opening and now seems to have disappeared from programs folder. MIdori is still crashing but lessl somewhat. Still libglib.dll error messages coming up.
    Online streaming is much better.
    There is still hardware wizard starting at beginning which I have to cancel.

    Thanks again and for any further help.

    Matthew
     

    Attached Files:

  7. mastermiaow

    mastermiaow Private First Class

    I have attached Roguekiller log after running it again. The problem before was logs were being saved in Roguekiller deep within C drive rather than desktop.
     

    Attached Files:

  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Everything else is fine, but this one you can have it remove:


    Then rescan to ensure it doesn't crop up again. Let me know. Then I think I can post final steps afterwards. :)
     
  9. mastermiaow

    mastermiaow Private First Class

    I deleted but it then reappeared as 'replaced' in PUMStart up (or something like that). Here is log attached.
    Thanks again:)
     

    Attached Files:

  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Sigh...

    Run the below...

    Please download AdwCleaner by Xplode and save to your Desktop.

    • Double click on AdwCleaner.exe to run the tool.
    • Vista/Windows 7/8 users right-click and select Run As Administrator
    • Click on the Scan button.
    • AdwCleaner will begin...be patient as the scan may take some time to complete.
    • After the scan has finished, click on the Report button...a logfile (AdwCleaner[R#].txt) will open in Notepad for review (where the largest value of # represents the most recent report).
    • The contents of the log file may be confusing. Unless you see a program name that you know should not be removed, don't worry about it. If you see an entry you want to keep, let me know about it.
    • Attach the logfile to your next next reply.
    • A copy of all logfiles are saved in the C:\AdwCleaner folder which was created when running the tool.
     
  11. mastermiaow

    mastermiaow Private First Class

    Is the sigh cos:

    • my laptop is particularly far gone?
      I am particularly far gone? ;)
    I ran the programme and cleaned as there was no way to close it down without doing so. I attach report log after scan and report log after clean. Midori still crashing and new hardware wizard still starting on start up and start up generally slow (latter perhaps just cos of small CPU).But things are running generally a lot more cleanly.
    Was wondering if I need anything else apart from IObit malware scanner and advanced system care, comodo fire wall and avast antivirus?

    Many thanks again

    Matthew
     

    Attached Files:

  12. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Just because it was being a little stubborn about being deleted, nothing to do with you. ;)

    Allow adwcleaner to remove what it finds and then rescan with RogueKiller. Attach log. :)
     
  13. mastermiaow

    mastermiaow Private First Class

    Hi
    Back again ;)
    Ran the adwcleaner then rogue killer. attached is report, I didn't delete the two PUMs that came up as waiting for your view.
    Still midori crashing but less and premium clock.exe coming up in task bar (think that is name for bar on bottom right) despite me deleitng it from start up items and can't find it programs to delete.

    Thanks again

    Matthew
     

    Attached Files:

  14. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Not a malware issue.
    You're welcome.

    Only thing left to do is minor, but I detest leaving anything behind.
    It's the conduit item RK keeps finding.

    I want you to follow the below instructions to reset Internet Explorer.

    Reset Internet Explorer 9, 10, and 11 to Defaults


    Run this and attach the results.

    Using ESET's Online Scanner

    Then once more rescan with RogueKiller and attach log.
     
  15. mastermiaow

    mastermiaow Private First Class

    I had more fun and games today trying to send you something via the laptop in question. Midori very very slow in loading web page, still has the libglib.dll error message flashing up and continuing to crash:cry
    IE has disappeared in terms of finding it via add remove programs or as an icon in the programmes panel. I did locate through the search function but it crashes almost immediately on opening. I have XP so I can't use IE 9 or later.

    To use ESET I need IE or Firefox (it says). I could try to download Firefox again?

    Thanks for advice :)
     
  16. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Yes then if the ESET scan doesn't find it I don't think we should worry about it too much. :)

    I'm afraid the broken IE is topic for the software forum.
     
  17. mastermiaow

    mastermiaow Private First Class

    Hi Kestrel

    downloaded firefox and ran Eset twice. Lots of teething problems getting it going and then it froze once the results were in so I couldn't attach report - 23 objects found, all seemed to be to do with downloaders such as Win32/softonic. I ran it again and it didn't find anything.

    Have run Roguekiller and it found two PUM in registry. report attached.

    Many thanks and nearly there.!

    Matthew
     

    Attached Files:

  18. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Are you able to reset your home page in internet explorer?
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds