PC extremely slow - logs

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Tony41, Jun 18, 2011.

  1. Tony41

    Tony41 Private E-2

    Hi Major Geeks Staff, and everyone. :)

    I'm writing from Italy, please forgive me for my poor English and eventual grammatical "horrors".

    All started a couple weeks ago, after installing a CD virtual software called MagicDisc which I then had to delete it from my system the "hard way" with a procedure found on the web, because he hadn't any uninstall procedure.

    It took me the whole day to follow the Malware removal procedures and I hope to have done things the right way. Please let me know if don't.

    I would like to take the opportunity to say that my PC is also suffering of system hang ups two or three times a day (sometimes more) with a sudden freeze of everything and subsequent automatic reboot after a few minutes (variable) with a brief blue screen which I can't read because of his very short appearance (milliseconds) before the reboot starts. May be this could be part of the problem...

    Here are my logs (two posts)
    (Some are in Italian, sorry for that. Is that a problem for you?) :-o

    Thanks you all in advance for any help.
     

    Attached Files:

    Last edited: Jun 18, 2011
  2. Tony41

    Tony41 Private E-2

    last log...
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I am not finding any malware in your logs. I suggest you post in the software forum for further assistance. You can get a BSOD error report by right clicking My Computer / Advanced / Start up and Recovery and uncheck the box to restart on errors. Post the contents of the BSOD in your thread in software.

    Since you are not having any malware problems, it is time to do our final steps:

    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.We recommend them for doing backup scans when you suspect a malware infection.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.


    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    10. After doing the above, you should work thru the below link:


    Malware removal from a National Chain = $149
    Malware removal from MajorGeeks = $0

    Help Support MajorGeeks
    Buy Discounted Software @ Majorgeeks Store. Giveaways Too!

    Majorgeeks Geek Wear. Hats, T-Shirts, Hoodies

    MajorGeeks on FaceBook
     
  4. Tony41

    Tony41 Private E-2

    Thank you Tim.

    I will follow your suggestion and will post the BSOD results in the software section next time it occurs.

    Even though, when hang up happened today (after uncheck the Automatic restart on errors as you requested), this time everything freeze except the cursor, and, after waiting for more than ten minutes, there was neither blue screen nor restart... I forced the reboot with the restart button.
    Just one more thing (sorry, but it also could be related with the malware removal procedure ran): I lost msconfig (Start>Run>msconfig)



    P.S.
    Next Wednesday June/22 I will travel overseas and probably unable to read/answer your replays, I will be out for three weeks. Anyway, I will try to keep in touch, even if I will be unable to work on the PC.I only have Monday and Tuesday left... Sorry for the inconvenient.
     
  5. Tony41

    Tony41 Private E-2

    LAST MINUTE UPDATE

    It hanged up again.
    This time I could read the blue screen, obviously, I couldn't make a Copy & Paste to show you the results, not to mention that is written in Italian, but, in other words, the fact is this:

    Quote:
    The problem seems to be caused by the nv4_disp file blocked in an endless loop.
    That means a problem with the peripheral or the driver.


    (Tony's note: Is that file related with the graphic card?)

    Tech. Info:

    *** stop: 0x000000EA (0x89504020, 0x89A86CB8, 0xB84DFCBC, 0x00000001)



    More Notes that could clarify:
    The original graphic board (ATI RAEDON Mod.X1050) was replaced for a new one (ASUS EN8400GS SILENT) +/- last February because a capacitor blown on the original board causing a total black out of the system, impeding us even to reboot. At that point, we didn’t know that the blackout was caused by the crashed graphic card, so we took the PC to the shop and they replaced the board and reinstalled the OS. Since then, I'm having those hang ups, but (I don't know why...) I never related it with the graphic card.

    Hope you understand my awful English... :-o



    I guess this problem must be posted on software or hardware section, you tell me, Thanks.
     
  6. Tony41

    Tony41 Private E-2

    In relation to the missing msconfig, I tried this (found in another thread):

    Quote:
    REGEDIT4

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\MSCONFIG.EXE]
    @="C:\\WINDOWS\\PCHealth\\helpctr\\Binaries\\MSCONFIG.EXE"


    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    After double clicking, I received a message asking if I wanted to insert data to the register, I said Yes. Soon after I got another message confirming that Info was inserted on System Register (sorry for not Copy & Paste the exact words of messages because they are in Italian...)
    Unfortunately, it didn't work; after rebooting, msconfig is not found :(
     
  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    If you haven't yet removed Combo, we need to replace one of the files.

    * Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    If it is not on your Desktop, the below will not work.
    * Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    * If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    * Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    KILLALL::
    
    DeQuarantine::
    C:\Qoobox\quarantine\c:\windows\system32\msconfig.exe.vir
    
    
    * Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    * At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    * You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    If it asks you to overide the previous file with the same name, click YES.
    * Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif
    * Follow the prompts.
    * When it finishes, a log will be produced named c:\combofix.txt
    * I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now go to the C:\windows\system32\msconfig.exe.vir and remove that .vir extension.

    Tell me if you can now get into msconfig.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Actually, ComboFix was correct in removing this as msconfig.exe does not belong in the system32 folder. If belongs only in the below location:

    C:\WINDOWS\PCHealth\helpctr\Binaries\MSCONFIG.EXE

    And that is where your registry setting was orginally showing to look for it in your first logs. But because it was in the system32 folder, it was just found by default.

    So if you want to restore it, restore it to the correct location so that it will not be suspected by other scanners again in the future.
     
    Last edited: Jun 19, 2011
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    One other observation! That msconfig.exe file was the wrong size for Win XP SP3. Where did it come from to begin with and who put it into the system32 folder? Was there a problem in the past and some one copied a file from another PC and put it into this folder?
     
  10. Tony41

    Tony41 Private E-2

    Hi TimW, Chaslang

    ComboFix was already deleted, so, in order to follow Tim's procedure, I downloaded it again unknowing, actually not remembering, that it would run again in automatic mode :-o

    Was that a big mistake? There is a new log... I haven't run the KILLALL procedure yet waiting for your instructions.

    chaslang, about msconfig wrong size, wrong place... I don't know what to say
    <<<Was there a problem in the past and some one copied a file from another PC and put it into this folder? >>> No, as long as I know, but the PC has been in a work shop a couple of times...



    Note:
    Local time here right now: 22:10
     
  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Since you already uninstalled it, the Qoobox folder is gone, so there is no backup to replace. Let's see if we can find the file somewhere else:

    Please download SystemLook from one of the links below and save it to your Desktop.
    Download Mirror #1
    Download Mirror #2


    • Double-click SystemLook.exe to run it.
    • Copy the content of the following codebox into the main textfield:
      Code:
      :filefind
      msconfig*
      
    • Click the Look button to start the scan.
    • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
    Note: The log can also be found on your Desktop entitled SystemLook.txt
     
  12. Tony41

    Tony41 Private E-2

    Unlucky... :(

    SystemLook 04.09.10 by jpshortstuff
    Log created at 22:25 on 19/06/2011 by Antonio Rosc
    Administrator - Elevation successful

    ========== filefind ==========

    Searching for "msconfig*"
    No files found.

    -= EOF =-
     
  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Do you have your OS install cd?
     
  14. Tony41

    Tony41 Private E-2

    No, they changed the OS last time the PC was at the work shop, when it had a problem with the graphic card, and I didn't ask details about it...
     
  15. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    The only way to replace that file is to use a XP pro install disc. Do you know anyone who you might borrow it from?
     
  16. Tony41

    Tony41 Private E-2

    Hi Tim, good morning.

    I found two files on my old OS CD copy (XP SP2) named MSCONFIG.CH_ (11 Kb) and MSCONFIG.EX_ (58 Kb). Are compressed files... can them be useful?

    Thank you for your valuable time.
     
  17. Tony41

    Tony41 Private E-2

    SO SORRY!!! :-o:-o:-o

    I didn't change section!!

    How can I move it?
    Hope Moderators can do it
    Thanks

    Really sorry guys.... :(
     
  18. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I move your question regarding the NVidia loop to the software forum:
    http://forums.majorgeeks.com/showthread.php?t=239588

    Can you save that file ( MSCONFIG.EX_ (58 Kb) ) to a cd? We might need to get into the Recovery Console to expand it.

    We can try using a command prompt. If your CD drive is D:

    Open a command prompt, type the following:
    CD D:
    Expand D:\MSCONFIG.EX_ C:\WINDOWS\PCHealth\helpctr\Binaries\MSCONFIG.EXE
    Exit.


     
  19. Tony41

    Tony41 Private E-2

    Thanks for moving my question Tim, I was quoting you and forgot to open a new thread... :-o

    Got msconfig.exe successfully expanded on C:\WINDOWS\PCHealth\helpctr\Binaries\MSCONFIG.EXE

    Sorry, I didn't understand the 'Exit' after the expand command...
    Should I do something else?
     
  20. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Exit is just the way to get out of the command prompt. So you did successfully get it expanded? It is now where it is supposed to be and you can now access msconfig?
     
  21. Tony41

    Tony41 Private E-2

    I got the 'Exit' now... :)

    I expanded using Start>Run... not with cmd prompt, sorry.

    I checked and found it in the correct folder: msconfig.exe 157 Kb 08/19/2004 but Start>Run>msconfig doesn't find it
     
  22. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    1.) Right click my computer->properties
    2.) Select advanced tab. Click Environment variables
    3.) In system variables section find the variable path.
    4.) Click edit. go to end of line and type
    c:\WINDOWS\pchealth\helpctr\binaries
    assuming your windows is in c drive.
     
  23. Tony41

    Tony41 Private E-2

    done!!

    Geee... what to say... you all are great people.
    Thanks for your time and support.
     
  24. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Good to know!! And you are most welcome. Safe surfing. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds