This is a read-only archive of malwareremoval.com. No new posts or registrations. Privacy Page
Malware Removal Forums

Windows 7 runs very slow and fails update

81 min read

This thread's last reply is from November 11, 2014, 4:01 PM UTC. Software, malware, and removal-tool advice below may be out of date — treat specific steps and download links with caution.

Computer seems to be running okay. I do get errors on starting Admin from Roxio but that should be taken care of with the fix. Below is the fislog;

Ran by [removed] at 2014-11-09 15:31:45 Run:2
Running from C:\Users\[removed]\Desktop
[removed]
Boot Mode: Normal

==============================================

Content of fixlist:
*****************
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\CodecPackUpdateChecker.lnk
Startup: C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Password Safe.lnk
HKLM\...\Run: [Acrobat Assistant 7.0] => C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe [483328 2004-12-14] (Adobe Systems Inc.)
HKLM\...\Run: [Adobe Version Cue CS2] => c:\Program Files\Adobe\Adobe Version Cue CS2\ControlPanel\VersionCueCS2Tray.exe [856064 2005-04-04] (Adobe Sytems Incorporated)
HKLM\...\Run: [APSDaemon] => C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe [43816 2014-07-31] (Apple Inc.)
HKLM\...\Run: [BrStsWnd] => C:\Program Files\Brownie\BrstsWnd.exe [3618104 2009-08-19] (brother)
HKLM\...\Run: [DMXLauncher] => C:\Program Files\Roxio\Media Experience\DMXLauncher.exe [102400 2006-11-14] ()
HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [152392 2014-08-01] (Apple Inc.)
HKLM\...\Run: [MediaFace Integration] => C:\Program Files\Fellowes\MediaFACE 5.0\SetHook.exe [53248 2009-02-02] (Fellowes, Inc.)
HKLM\...\Run: [QuickTime Task] => C:\Program Files\QuickTime\QTTask.exe [421888 2014-01-17] (Apple Inc.)
HKLM\...\Run: [RoxioDragToDisc] => C:\Program Files\Roxio\Drag-to-Disc\DrgToDsc.exe [1121016 2006-11-15] (Roxio)
HKLM\...\Run: [RoxWatchTray] => C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe [221184 2006-11-27] (Sonic Solutions)
HKLM\...\Run: [SDTray] => "C:\Program Files\Spybot - Search & Destroy 2\SDTray.exe"

*****************

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\CodecPackUpdateChecker.lnk => Moved successfully.
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Password Safe.lnk => Moved successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\Acrobat Assistant 7.0 => value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\Adobe Version Cue CS2 => value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\APSDaemon => value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\BrStsWnd => value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\DMXLauncher => value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\iTunesHelper => value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\MediaFace Integration => value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\QuickTime Task => value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\RoxioDragToDisc => value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\RoxWatchTray => value deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\SDTray => value deleted successfully.

==== End of Fixlog ====
In that case, as far as I can see your computer is now clear of infection, and all that remains for us to do, is to remove the programs we've been using to clean your machine.

  • Please download delfix and save it to your desktop.
  • Right-click on delfix.exe and select " Run as administrator " to run it.
  • Check all the boxes then click on Run.
  • Once it has finished, a notepad file named DelFix.txt will open. Post the contents of this notepad in your next reply.
  • The log can also be located at the root of the system drive, C:\DelFix.txt.


Please read the article below which will give you a few suggestions for how to minimise your chances of getting another infection.
DelFix


# DelFix v10.8 - Logfile created 10/11/2014 at 10:01:22
# Updated 29/07/2014 by Xplode
# Username : admin - OTTERSEA
# Operating System : Windows 7 Home Premium Service Pack 1 (32 bits)

~ Activating UAC ... OK

~ Removing disinfection tools ...

Deleted : C:\Combofix
Deleted : C:\FRST
Deleted : C:\AdwCleaner
Deleted : C:\Users\admin\Desktop\FRST-OlderVersion
Deleted : C:\ComboFix.txt
Deleted : C:\Users\admin\Desktop\Addition.txt
Deleted : C:\Users\admin\Desktop\AdwCleaner[R0].txt
Deleted : C:\Users\admin\Desktop\adwcleaner_3.311.exe
Deleted : C:\Users\admin\Desktop\dds.txt
Deleted : C:\Users\admin\Desktop\Fixlog.txt
Deleted : C:\Users\admin\Desktop\FRST.exe
Deleted : C:\Users\admin\Desktop\FRST.txt
Deleted : C:\Users\admin\Desktop\Search.txt
Deleted : C:\Windows\NIRCMD.exe
Deleted : HKLM\SOFTWARE\AdwCleaner
Deleted : HKLM\SOFTWARE\Swearware

~ Creating registry backup ... OK

~ Cleaning system restore ...

Deleted : RP #481 [Scheduled Checkpoint | 11/08/2014 01:31:14]

New restore point created !

~ Resetting system settings ... OK

########## - EOF - ##########
Okay. Right after I did the above my computer totally locked up. Had no mouse, control-alt-delete did nothing. Finally had to turn it off and reboot the computer. So far all seems good except for that lock up. Only thing I did was reinstall spybot. Any ideas why it did that?
I've no idea why you locked up, I can't see anything that's been removed that should have caused that kind of incident.

Keep an eye on your computer for the next couple of days, and if it does anything else unexpected, then post back here and let me know.

If I haven't heard back from you by Wednesday I'll presume everything is behaving itself and I'll close the topic.
Okay. Seems to be okay and do not know what locked it up. If it continues to do that I will open another topic on that at a later date.
In that case, as your problems appear to have been resolved,