Laptop slow to boot and unstable

Discussion in 'Malware Help (A Specialist Will Reply)' started by amellon, Dec 27, 2007.

  1. amellon

    amellon Private E-2

    Not sure anyone can help me with this but here goes - Was traveling several weeks ago and took along laptop which kids used on hotel computer networks - Not sure this is related, but since then laptop has gotten consistently slower and less responsive. Takes more than ten minutes to boot and then hangs up with hour glass running for another ten minutes. Could also be that there is hardware problem. I know nothing about technical side of computers. Ran tests as directed and attempted to save related files. Not sure how successful I was. If anyone could help it would be appreciated. If not, I think a new laptop is in my future. While system seemed a little more stable after running recommended programs, still is not right. thanks for any help. AVG gave message "no reports available".
     

    Attached Files:

  2. abri

    abri MajorGeek

    Hi amellon!
    Welcome to Major Geeks!

    Your tools didn't run correctly, but I can see from one of the scans that your computer is infected. I would like to ask you to run the following scans which are lengthy and thorough. The BitDefender will look at archived data which most scans don't bother with and it will also check your restore points. The Panda scan simply finds things that other scans miss. Be sure to have BitDefender fix anything it finds and follow our instructions which will allow you to produce the log we need. Panda will fix the most harmful things and leave the rest.

    Could you tell if AVG ran and found and fixed things even though it did not offer a log?

    Here are the instructions for the two above scans. Important! You must use Internet Explorer (not another browser) to run these scans!!

    To start with, you MUST be sure that MSconfig is not being used to control Startups.
    • MSConfig Startup Mode
      Please go to Start > Run > type msconfig and click OK!
      Select the General tab and select Normal Startup.
    Thenclick Apply and OK and reboot PC before continuing.​
    Remain in this Normal Startup mode while your PC is being cleaned of malware.


    *** MAKE SURE YOU RUN BITDEFENDER BEFORE PANDA ACTIVE SCAN ***
    *** But if Bitdefender cannot be run then run PandaActiveScan anyway ***

    ****NOTE**** DO NOT INSTALL Bitdefender's Antivirus program. Make sure you follow the directions below and run the ONLINE SCANNER only.


    Bitdefender agree to the license and then select Scan. DO NOT CHANGE THE OPTIONS TO SHOW ALL FILES SCANNED. That will make your logs huge and we don't need to see clean files. Once Bitdefender completes the scan:

    Click-on the Detected Problems tab. Then select Click here to export the scan report

    When the window comes up to save the report, change the Save as type: box to Text (Tab Delimited) (*.txt) and then in the File name box enter change to bdscan then click save. This will save a file named bdscan.txt in whatever folder you are currently in when you save the file (take notice of where you are at so you can find it later). This bdcan.txt file will actually contain HTML code that we can easily view later while reviewing your log. All we have to do is rename the file to bdscan.html.

    If you do not follow these steps, you will have an incorrect log or worse a log summary which is useless to us.

    Post the bdscan.txt file as an ATTACHMENT. See: HOW TO: Attach Items To Your Post
    You MUST attach the Bitdefender log even it it indicates no problems. We want to see it anyway!!!! Also if you run things out of order you will notice BitDefender showing the below which is a false detection from PandaActiveScan:


    C:\WINDOWS\system32\ActiveScan\pskahk.dll
    Infected with: Generic.Malware.SIMDWYNVdprn.D9407F4E
    • Panda ActiveScan It will only fix certain viruses and trojans. Most items found will not be fixed. When it finishes the scan click on See Report . Then in the next window click Save Report. The default report name is Activescan.txt. Just save it where you can find it so you can attach to your message when you begin a thread with a request for help. If you have any problems trying to get a PandaActiveScan log, see the following link with more detail and follow it step by step: Using PandaActiveScan
    If you use Avast antivirus and it gives you an error like below when trying to use Panda, just disable Avast while you run the scan. The error is a false positive. See the below link for more info.
    After you finish the above, please attach the BitDefender and Panda logs with your next post.

    Also, I will need to see the MGlogs.zip again. I'm not sure why they didn't run correctly. Did you click on MGtools.exe and allow it to install under the directory where your operating system is located? You should have a folder in that directory (usually C:\) called MGTools.

    abri
     
  3. amellon

    amellon Private E-2

    Abri - As instructed I am attaching files from both scans. Once again I also attempted to run Mglogs - and am attaching results - when I run that program I get several error messages concerning autoexec.nt not suitable for DOS or windows programs? In any case I have attached what I did - thanks for your help on this
     

    Attached Files:

  4. amellon

    amellon Private E-2

    Abri - Failed to mention that when computer does boot a message about windows defender not loading appears - not sure if that is relevant
     
  5. abri

    abri MajorGeek

    Hi amellon!
    Happy New Year!


    I'm not sure why your MGtools aren't working correctly. If they won't work as a set, I will ask you to install them separately and run them. They are not time-consuming. Please do the following. It will produce a log that you can post back to me.

    Download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Check the 'Input script manually' box.
    • Click on the magnifying glass icon.
    • Copy everything in the Quote box below, and paste it in the box that opens:
    • Now click the 'Done' button.
    • Click on the traffic light icon and OK the prompt.
    • You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt
    If Avenger deletes either or both of these, please run CCleaner afterwards.


    Make sure you tell me how things are working now!




    abri
     
  6. amellon

    amellon Private E-2

    Abri - Happy New Year to you as well and I do appreciate the help.

    Could you expand a little on the installation of MGtools - i.e. installing them separately. Again, thanks for the help.
     
  7. abri

    abri MajorGeek

    Hi Amellon!

    There are two links here. The first for Using ShowNew will give you instructions for installing and running the program called ShowNew. It produces a log called newfiles.txt. There are a lot of instructions to deal with exceptions and to tell you about possible problems, but the actual installation program is in the zip file at the very bottom of the page.

    Using ShowNew


    Locate the shownew.bat file and double click on it to run it. It will create a file named newfiles.txt in the root of drive C: (C:\newfiles.txt) . This log will also popup in a notepad window which your can just close. Upload the newfiles.txt file here as an attachment when you come back to post your results.

    ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------

    The second link is here and will give you the instructions for how to install and run HijackThis which must be renamed to Analyse.exe. Please go to the link and read through the instructions to figure out where the program should be located before you run it. Neither ShowNew nor HijackThis take long to run. Less than a minute each. After you finishe them both, please attach the logs to your next post.


    You must install HijackThis properly per the instructions in the below link.

    ***** MAKE SURE YOU CLICK THE BELOW LINK AND FOLLOW DIRECTIONS! TOO MANY PEOPLE ARE SKIPPING IT! *****

    Downloading, Installing, and Running HijackThis


    abri
     
  8. amellon

    amellon Private E-2

    Two files per your instruction
     

    Attached Files:

  9. abri

    abri MajorGeek

    Hi amellon!

    I don't see a resident antivirus or firewall on your system. Am I overlooking them?

    1) The very important thing in our HijackThis instructions is for you to rename hijackthis.exe to analyse.exe

    We do this because there are certain viruses which have learned to evade detection from HijackThis.

    After you finish with the following instructions, please rerun it with the correct name. Simply go to its location in Windows Explorer, find hijackthis.exe and right click on it, select rename and enter the new name in the box where the old file name is.

    2) In post # 5 I asked you to run Avenger. Could you attach the log from that for me so I can see if those two entries were deleted?

    Before you do the above, please do the following:

    3) Go to add/remove programs and uninstall the below:

    - Viewpoint Media Player
    - J2SE Runtime Environment 5.0 Update 1
    - J2SE Runtime Environment 5.0 Update 2
    - J2SE Runtime Environment 5.0 Update 4
    - Java 2 Runtime Environment, SE v1.4.1_06
    - Java 2 Runtime Environment, SE v1.4.2
    - Java 2 Runtime Environment, SE v1.4.2_08


    4) Reboot after uninstalling the above.

    5) Install the current version of Sun Java from: Sun Java Runtime Environment


    6) If you do not use Windows Messenger (not to be confused with MSN Messenger!!) I would like you to run Disable/Remove Windows Messenger


    7) Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Check the 'Input script manually' box.
    • Click on the magnifying glass icon.
    • Copy everything in the Quote box below, and paste it in the box that opens:
    • Now click the 'Done' button.
    • Click on the traffic light icon and OK the prompt.
    • You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt
    8) Please run CCleaner.

    9) When you finish the above, please run analyse.exe and post the new log along with the Avenger log.


    Let me know how everything went.
    abri
     
  10. amellon

    amellon Private E-2

    Thought I changed name - must have been zip file i changed- sorry
     

    Attached Files:

  11. amellon

    amellon Private E-2

    Meant to mention that I normally use windows firewall and AVG antivirus. Think I had these turned off while I was trying to stablize computer. Again, thanks for all your help.
     
  12. abri

    abri MajorGeek

    Hi amellon,
    I haven't heard if any of the instructions we've given you has made any difference in the way your computer is running. It is possible that you have something like a bad sector on your harddisk, which can also cause the kind of symptoms you describe. I don't know if you've checked your harddisk for defective sectors, but you can do that by opening My Computer and marking which drive you want to check, then right click for properties / tools and under tools there are three boxes. The first one should be Error Check. Allow that to check your disk.

    I don't find any further signs of malware so I would like to post the final cleaning instructions to you. Your BitDefender scan did not pick up any infected restore points, so at this point I would simply leave the restore points as they are rather than resetting them. If you have them turned off, you should turn them on, because they can be useful. After you finish the below, I would like to suggest posting in the Hardware Forum and see if they can help you further.

    abri
     
  13. amellon

    amellon Private E-2

    Thanks for all your help Abri - the system runs smoother and seems more stable once it boots. It still takes quite a while to boot up and the hour glass runs for a significant amount of time after that. A message comes up that windows defender is being stopped from loading. I suspect it may be time for a new laptop. Again, thanks for your help and it is an improvement which should get me through until I can get a new system.
     
  14. abri

    abri MajorGeek

    Hi amellon!

    I noticed in your last hijackthis that your old java programs seem to still be installed. Did you remove them via add/remove programs and install the new one as per the instructions in Step 9?

    abri
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds