Jump to content

Freezing or extremely slow at start up - possible infection or ?


Recommended Posts

The system required a reboot to finish removing files. Here's the OTL log:

All processes killed

========== FILES ==========

C:\Users\Joan\AppData\Roaming\Azureus\torrents folder moved successfully.

C:\Users\Joan\AppData\Roaming\Azureus\tmp folder moved successfully.

C:\Users\Joan\AppData\Roaming\Azureus\subs folder moved successfully.

C:\Users\Joan\AppData\Roaming\Azureus\shares folder moved successfully.

C:\Users\Joan\AppData\Roaming\Azureus\rss folder moved successfully.

C:\Users\Joan\AppData\Roaming\Azureus\plugins\mlab folder moved successfully.

C:\Users\Joan\AppData\Roaming\Azureus\plugins\azutp\x64 folder moved successfully.

C:\Users\Joan\AppData\Roaming\Azureus\plugins\azutp\win32 folder moved successfully.

C:\Users\Joan\AppData\Roaming\Azureus\plugins\azutp folder moved successfully.

C:\Users\Joan\AppData\Roaming\Azureus\plugins\azupnpav folder moved successfully.

C:\Users\Joan\AppData\Roaming\Azureus\plugins\aefeatman_v folder moved successfully.

C:\Users\Joan\AppData\Roaming\Azureus\plugins folder moved successfully.

C:\Users\Joan\AppData\Roaming\Azureus\net folder moved successfully.

C:\Users\Joan\AppData\Roaming\Azureus\logs folder moved successfully.

C:\Users\Joan\AppData\Roaming\Azureus\dht folder moved successfully.

C:\Users\Joan\AppData\Roaming\Azureus\devices folder moved successfully.

C:\Users\Joan\AppData\Roaming\Azureus\active folder moved successfully.

C:\Users\Joan\AppData\Roaming\Azureus folder moved successfully.

c:\Users\AppData\LocalLow\Conduit\Community Alerts\Log folder moved successfully.

c:\Users\AppData\LocalLow\Conduit\Community Alerts folder moved successfully.

c:\Users\AppData\LocalLow\Conduit folder moved successfully.

========== COMMANDS ==========

[EMPTYTEMP]

User: All Users

User: AppData

->Temp folder emptied: 0 bytes

User: Default

->Temp folder emptied: 0 bytes

->Temporary Internet Files folder emptied: 0 bytes

->Flash cache emptied: 0 bytes

User: Default User

->Temp folder emptied: 0 bytes

->Temporary Internet Files folder emptied: 0 bytes

->Flash cache emptied: 0 bytes

User: Joan

->Temp folder emptied: 5232370 bytes

->Temporary Internet Files folder emptied: 2508968 bytes

->Java cache emptied: 0 bytes

->FireFox cache emptied: 18506342 bytes

->Google Chrome cache emptied: 0 bytes

->Apple Safari cache emptied: 0 bytes

->Flash cache emptied: 492 bytes

User: Public

->Temp folder emptied: 0 bytes

%systemdrive% .tmp files removed: 0 bytes

%systemroot% .tmp files removed: 0 bytes

%systemroot%\System32 .tmp files removed: 0 bytes

%systemroot%\System32 (64bit) .tmp files removed: 0 bytes

%systemroot%\System32\drivers .tmp files removed: 0 bytes

Windows Temp folder emptied: 4444 bytes

%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 0 bytes

%systemroot%\sysnative\config\systemprofile\AppData\LocalLow\Sun\Java\Deployment folder emptied: 0 bytes

RecycleBin emptied: 25741584 bytes

Total Files Cleaned = 50.00 mb

[EMPTYFLASH]

User: All Users

User: AppData

User: Default

->Flash cache emptied: 0 bytes

User: Default User

->Flash cache emptied: 0 bytes

User: Joan

->Flash cache emptied: 0 bytes

User: Public

Total Flash Files Cleaned = 0.00 mb

[EMPTYJAVA]

User: All Users

User: AppData

User: Default

User: Default User

User: Joan

->Java cache emptied: 0 bytes

User: Public

Total Java Files Cleaned = 0.00 mb

Restore point Set: OTL Restore Point

OTL by OldTimer - Version 3.2.69.0 log created on 05302013_115409

Files\Folders moved on Reboot...

C:\Users\Joan\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.

C:\Users\Joan\AppData\Local\Microsoft\Windows\Temporary Internet Files\counters.dat moved successfully.

PendingFileRenameOperations files...

Registry entries deleted on Reboot...

Link to post
Share on other sites

  • Replies 54
  • Created
  • Last Reply

Top Posters In This Topic

We can wrap this up now. I see that you are clear of your original issues.

If you have a problem with these steps, or something does not quite work here, do let me know.

The following few steps will remove tools we used. Advise me after you have completed the cleanups.

  • Download OTC to your desktop and run it
  • Click Yes to beginning the Cleanup process and remove these components, including this application.
  • You will be asked to reboot the machine to finish the Cleanup process. Choose Yes.

ERUNT you should keep and use periodically to backup Windows registry.

To re-enable CD Emulation programs using DeFogger please perform these steps:

Please download >> DeFogger <<and save it to your desktop.

  • Once downloaded, double-click on the DeFogger icon to start the tool.
  • The application window will appear.
  • You should now click on the Enable button to re-enable your CD Emulation drivers.
  • When it prompts you whether or not you want to continue, please click on the Yes button to continue.
  • When the program has completed you will see a Finished! message. Click on the OK button to exit the program.
  • If CD Emulation programs are present and have been enabled, DeFogger will now ask you to reboot the machine. Please allow it to do so by clicking on the OK button.

Delete the following if still present:

Frst64.exe

adwcleaner.exe

roguekiller.exe

Tdsskiller.exe

securitycheck.exe

Stinger.exe

You should create a "system repair disc" for your Windows 7 either to a CD, DVD, or new USB-flash-thumb drive {if your hardware can boot from USB}.

The following is a reference page at Microsoft and also has a link to a how-to-video.

Create a Windows 7 system repair disc

This "repair disc" is a very handy tool that one may use when and IF you are not able to start Windows 7 normally.

This "repair disc" or "rescue disc" is not intended as a replacement for having the Windows 7 operating system DVD.

Make a rescue disc, put a label on it, store it away for a "rainy day".

Safer practices & malware prevention

We are finished here. Best regards. cool.gif

Link to post
Share on other sites

hold down the SHIFT-key when you inserting the USB-flash- thumb drive.

Scan any file with your Antivirus prior to opening or using.

You can view the drives thru Windows Explorer, do a right-click on the drive, and you should have a right-click context menu, with several options, including scanning with MalwareBytes or your antivirus.

That is probably the fastest easiest to use.

In addition, Download and run "Flash Drive Disinfector" by sUBs. It will do a cleanup of removable storage devices, and write a protected Autorun.inf file to help prevent re-infection.

http://download.bleepingcomputer.com/sUBs/Flash_Disinfector.exe

There is no GUI interface or log file produced.

Very happy to have helped. All the best to you.

Link to post
Share on other sites

Guest
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.

Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.