Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

Very slow computer, aswMBR rootkit not working [Closed]

aswMBR Slow

  • This topic is locked This topic is locked

#31
dbreeze

dbreeze

    Trusted Helper

  • Malware Removal
  • 2,216 posts

Hey, welcome back Spencer4134. Let's see if we can't get some of the issues cleared for good.

First, OTL fix >>>

Note: The script text listed below is for this user / system only. Any other useage may lead to system damage and is not condoned or advised.

Please right click on the OTL file on your desktop and select Run as Administrator.

Copy the fix text in the code box below by clicking at the : in the left corner and dragging the mouse curser to the bottom past the ] in the last line, right click and select COPY.

Return to the OTL menu that is open, right click on the open box below Custom Scans/Fixes and select PASTE. If you did this properly, the first line in the Custom Scans/Fixes box should read :processes and the last line should read [EMPTYTEMP] .

Click on the Run Fix button.

OTL will process the fix text, close the desktop, reboot your system and produce a log file named MMDDYYYY_hhmmss.log . If the log is not opened in Notepad after the system reboots, you can find the file in the C:\_OTL\MovedFiles directory. Please copy and paste the log file contents in a reply post here.

This is the code box with the Fix Text to copy =>

:processes

:OTL
FF:64bit: - HKLM\Software\MozillaPlugins\@bestbuy.com/npBestBuyPcAppDetector,version=1.0: C:\ProgramData\Best Buy pc app\npBestBuyPcAppDetector.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@bestbuy.com/npBestBuyPcAppDetector,version=1.0: C:\ProgramData\Best Buy pc app\npBestBuyPcAppDetector.dll File not found
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
O3:64bit: - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:64bit: - Protocol\Handler\ms-itss - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\mso-offdap11 - No CLSID value found
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
[2014/02/26 19:07:48 | 000,000,000 | ---D | M] -- C:\Users\Conrad Bowen\AppData\Roaming\Free Download Manager
[2011/08/27 13:09:27 | 000,000,000 | ---D | M] -- C:\Users\Conrad Bowen\AppData\Roaming\Nitro PDF
[2011/09/30 14:49:24 | 000,000,000 | ---D | M] -- C:\Users\Conrad Bowen\AppData\Roaming\PrimoPDF

:Services

:Reg

:Files
C:\ProgramData\Best Buy pc app\npBestBuyPcAppDetector.dll

:commands
[EMPTYTEMP]


Second, a SFC scan >>>>

Please run a SFC scan on this system when it restarts. There where a few services not found in the OTL logs and we need to make sure that Windows says that is proper.

You can run this scan by doing the following:
Click on Start > All Programs > Accessories, then right click on Command Prompt and select "Run as Administrator". Then type the following into the command line (with an Enter after each line).

sfc /scannow

(Notice the SPACE after sfc and before the /.)

This will check your critical system files. Does this finish without complaint?

IF it does then just report that and skip the rest of this routine and goto the next step.
IF it says it couldn't fix everything then:

Copy the next two lines:

findstr /c:"[SR]" \windows\logs\cbs\cbs.log > \windows\logs\cbs\junk.txt
notepad \windows\logs\cbs\junk.txt

Click on Start > All Programs > Accessories, right click on Command Prompt and select "Run as Administrator". Right click and select Paste or Edit then Paste and the copied lines should appear.
Hit Enter if notepad does not open. Copy and paste the text from Notepad into a reply. Close Notepad once the log is pasted. Close the Command Window.

Third, refresh BitDefender >>>>

Please follow the steps listed in the BitDefender Help page here to repair the installation of BitDefender Total Security 2015. This should help with the startup of the system as BitDefender's VSSERV service was hanging on system startup.

Finally, a disk Defrag >>>>

You can run a defragmentation process on the drive C by going to Start > Computer > right click on the C drive (in the right hand pane) and select Properties. Click on the Tools tab and then click on "Defragment now..."

If you want to go to the next level in trying to shorten the boot time, you can follow the quideline here, also.


Replies we need to see >>>>

  • The OTL fix log.
  • How did the sfc scan go? If there are any errors, please post that log also.
  • Did the repair of BitDefender work?
  • How is the system running now?

  • 0

Advertisements


#32
Spencer4134

Spencer4134

    Member

  • Topic Starter
  • Member
  • PipPip
  • 57 posts
Ok I ran the OTL fix, system file checker went great. Repaired Bitdefender, but while I was defragging, I noticed the Bitdefender task bar icon was gray. Hovered over it and it said Bitdefender was unresponsive and I needed to restart. The Defrag was still at 0% so I cancelled it and restarted. Now, "your computer was unable to start" appears and the startup repair is trying to fix it. I'm not panicking, but, WHAT. IS. GOING. ON.
  • 0

#33
Spencer4134

Spencer4134

    Member

  • Topic Starter
  • Member
  • PipPip
  • 57 posts

Ok, so I have now booted with the last successful boot settings. Please let me know what I should do next as soon as you can.

 

OTL:

 

All processes killed
========== PROCESSES ==========
========== OTL ==========
64bit-Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@bestbuy.com/npBestBuyPcAppDetector,version=1.0\ deleted successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@microsoft.com/GENUINE\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@bestbuy.com/npBestBuyPcAppDetector,version=1.0\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@microsoft.com/GENUINE\ deleted successfully.
64bit-Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\10 deleted successfully.
64bit-Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\Locked deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\10 deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\Locked deleted successfully.
Registry value HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\RunOnce\\mctadmin deleted successfully.
Registry value HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\RunOnce\\mctadmin deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\URL\Prefixes\\gopher|:gopher:// /E : value set successfully!
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\livecall\ deleted successfully.
File Protocol\Handler\livecall - No CLSID value found not found.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\ms-help\ deleted successfully.
File Protocol\Handler\ms-help - No CLSID value found not found.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\ms-itss\ deleted successfully.
File Protocol\Handler\ms-itss - No CLSID value found not found.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\msnim\ deleted successfully.
File Protocol\Handler\msnim - No CLSID value found not found.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\mso-offdap11\ deleted successfully.
File Protocol\Handler\mso-offdap11 - No CLSID value found not found.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\wlmailhtml\ deleted successfully.
File Protocol\Handler\wlmailhtml - No CLSID value found not found.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\wlpg\ deleted successfully.
File Protocol\Handler\wlpg - No CLSID value found not found.
C:\Users\Conrad Bowen\AppData\Roaming\Free Download Manager folder moved successfully.
C:\Users\Conrad Bowen\AppData\Roaming\Nitro PDF\Reader\2.0\JavaScripts folder moved successfully.
C:\Users\Conrad Bowen\AppData\Roaming\Nitro PDF\Reader\2.0 folder moved successfully.
C:\Users\Conrad Bowen\AppData\Roaming\Nitro PDF\Reader folder moved successfully.
C:\Users\Conrad Bowen\AppData\Roaming\Nitro PDF folder moved successfully.
C:\Users\Conrad Bowen\AppData\Roaming\PrimoPDF folder moved successfully.
========== SERVICES/DRIVERS ==========
========== REGISTRY ==========
========== FILES ==========
File\Folder C:\ProgramData\Best Buy pc app\npBestBuyPcAppDetector.dll not found.
========== COMMANDS ==========
 
[EMPTYTEMP]
 
User: All Users
 
User: Conrad Bowen
->Temp folder emptied: 62006980 bytes
->Temporary Internet Files folder emptied: 126277 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 108255051 bytes
->Flash cache emptied: 18580 bytes
 
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
 
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
 
User: Public
 
%systemdrive% .tmp files removed: 26908 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 142 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 128 bytes
RecycleBin emptied: 0 bytes
 
Total Files Cleaned = 163.00 mb
 
 
OTL by OldTimer - Version 3.2.69.0 log created on 09112014_150343

Files\Folders moved on Reboot...
C:\Users\Conrad Bowen\AppData\Local\Temp\acrord32_sbx\[email protected] moved successfully.
C:\Users\Conrad Bowen\AppData\Local\Temp\acrord32_sbx\[email protected] moved successfully.
C:\Users\Conrad Bowen\AppData\Local\Temp\acrord32_sbx\[email protected] moved successfully.
C:\Users\Conrad Bowen\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.
C:\Users\Conrad Bowen\AppData\Local\Microsoft\Windows\Temporary Internet Files\counters.dat moved successfully.
File\Folder C:\windows\temp\~bd2408.tmp not found!

PendingFileRenameOperations files...

Registry entries deleted on Reboot...

 

Bitdefender seems to be working now... I think I'm gonna run the defrag. Hopefully that will help.


  • 0

#34
dbreeze

dbreeze

    Trusted Helper

  • Malware Removal
  • 2,216 posts

Spencer4134,

 

You actually did exactly what should have been done; the system is running as it should be (sounds like it needed one extra reboot after the repair install of BitDefender).  Let us know how the system is after the defrag run.


  • 0

#35
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
Due to lack of feedback, this topic has been closed.

If you need this topic reopened, please contact a staff member. This applies only to the original topic starter. Everyone else please begin a New Topic.
  • 0






Similar Topics


Also tagged with one or more of these keywords: aswMBR, Slow

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP