2011-07-14, 19:35
You guys have helped before, giving it another shot. My PC seems to get slower daily. Things like videos and music (both online and from media) are choppy and unreliable


2011-07-20, 15:21
Please note that all instructions given are customised for this computer only, the tools used may cause damage if used on a computer with different infections.

If you think you have similar problems, please post the appropriate logs in the Malware Removal forum and wait for help.
Hi and welcome back to Safer Networking. :)

I'm Dakeyras and I am going to try to assist you with your problem. Please take note of the below:

I will start working on your Malware issues, this may or may not, solve other issues you have with your machine.
The fixes are specific to your problem and should only be used for this issue on this machine!
The process is not instant. Please continue to review my answers until I tell you your machine is clear. Absence of symptoms does not mean that everything is clear.
If you don't know, stop and ask! Don't keep going on.
Please reply to this thread. Do not start a new topic.
Refrain from running self fixes as this will hinder the malware removal process.
It may prove beneficial if you print of the following instructions or save them to notepad as I post them.
Your security programs may give warnings for some of the tools I will ask you to use. Be assured, any links I give are safe.
Windows 7 Advice:

All applications I ask to be used will require to be run in Administrator mode. IE: Right click on and select Run as Administrator.

The Operating System in use comes with a inbuilt utility called User Access Control(UAC) when prompted by this with anything I ask you to do carry out please select the option Allow.

Before we start:

Please be aware that removing Malware is a potentially hazardous undertaking. I will take care not to knowingly suggest courses of action that might damage your computer. However it is impossible for me to foresee all interactions that may happen between the software on your computer and those we'll use to clear you of infection, and I cannot guarantee the safety of your system. It is possible that we might encounter situations where the only recourse is to re-format and re-install your operating system, or to necessitate you taking your computer to a repair shop.

Because of this, I advise you to backup any personal files and folders before you start.

Create a System Restore Point:

Right click on Computer and select Properties >> System protection >> Create.
Give this restore point a descriptive name and click Create.
When done, click Apply >> OK.

Scan with OTL:

Please download OTL (http://oldtimer.geekstogo.com/OTL.exe) and save it to your Desktop.

Alternate downloads are here (http://oldtimer.geekstogo.com/OTL.com) and here (http://oldtimer.geekstogo.com/OTL.scr).

Right-click on OTL.exe and select Run as Administrator to start OTL.
Ensure Include 64bit Scans is selected.
Under Output, ensure that Minimal Output is selected.
Under Extra Registry section, select Use SafeList.
Click the Scan All Users checkbox.
Click on Run Scan at the top left hand corner.
When done, two Notepad files will open.
OTL.txt <-- Will be opened
Extra.txt <-- Will be minimized
Please post the contents of these 2 Notepad files in your next reply.
When completed the above, please post back the following in the order asked for:

How is your computer performing now, any further symptoms and or problems encountered?
Both OTL logs. <-- Post them individually please, IE: one Log per post/reply.

2011-07-20, 17:38
Thanks for the reply, Dakeryras. My PC continues to be slower on what seems to be a daily basis. It is slowly getting worse.

Per your request, the otl.txt file:

2011-07-22, 00:53
Hi. :)

Things are still quite slow with the PC, although perhaps a big faster since the scan.
OK, lets proceed as follows shall we...

OTL reported there was a error creating a system restore point. Please check it is active as follows:-

Right click on Computer and select Properties >> System protection


Please download this small application from here (http://www.malwarebytes.org/startuplite.php).

It is very simple to use and quite effective and will advise about any unnecessary system startups that can be safely removed.

ESET Online Scanner:

Note: You can use either Internet Explorer or Mozilla FireFox for this scan. You will however need to disable your current installed Anti-Virus, how to do so can be read here (http://www.bleepingcomputer.com/forums/topic114351.html).

Windows 7 users: You will need to to right-click on the either the IE or FF icon in the Start Menu or Quick Launch Bar on the Taskbar and select Run as Administrator from the context menu.

Please go here (http://www.eset.com/onlinescan/) click on Run ESET Online Scanner.
Note: If using Mozilla Firefox you will need to download esetsmartinstaller_enu.exe when prompted then double click on it to install.
All of the below instructions are compatible with either Internet Explorer or Mozilla FireFox. Select the option YES, I accept the Terms of Use then click on: http://i280.photobucket.com/albums/kk173/Dakeyras_album2/EOLS2.gif
When prompted allow the Add-On/Active X to install.
Make sure that the option Remove found threats is NOT checked, and the option Scan archives is checked.
Now click on Advanced Settings and select the following:
Scan for potentially unwanted applications
Scan for potentially unsafe applications
Enable Anti-Stealth Technology
Now click on: http://i280.photobucket.com/albums/kk173/Dakeyras_album2/EOLS3.gif
The virus signature database... will begin to download. Be patient this make take some time depending on the speed of your Internet Connection.
When completed the Online Scan will begin automatically.
Do not touch either the Mouse or keyboard during the scan otherwise it may stall.
When completed select Uninstall application on close if you so wish, make sure you copy the logfile first!
Now click on: http://i280.photobucket.com/albums/kk173/Dakeyras_album2/EOLS4.gif
Use notepad to open the logfile located at : C:\Program Files (x86)/ESET/ESET Online Scanner\log.txt.
Copy and paste that log as a reply to this topic.
Note: Do not forget to re-enable your Anti-Virus application after running the above scan!

2011-07-22, 23:00
No nasties found:

ESETSmartInstaller@High as downloader log:
all ok
# version=7
# OnlineScannerApp.exe=
# OnlineScanner.ocx=
# api_version=3.0.2
# EOSSerial=6d4ebb59d029414d8d87769f432f8fd5
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=true
# antistealth_checked=true
# utc_time=2011-07-22 07:24:06
# local_time=2011-07-22 03:24:06 (-0500, Eastern Daylight Time)
# country="United States"
# lang=1033
# osver=6.1.7601 NT Service Pack 1
# compatibility_mode=512 16777215 100 0 0 0 0 0
# compatibility_mode=5893 16776574 100 94 2096848 62884999 0 0
# compatibility_mode=8192 67108863 100 0 0 0 0 0
# scanned=195973
# found=0
# cleaned=0
# scan_time=21095

2011-07-22, 23:18
The system is running much, much faster now since the reboot.

Could it have something to do with changing the system protection settings? That's the only thing that has changed?! :confused:

2011-07-23, 14:07
Hi. :)

What you mentioned is feasible as the feature with Windows 7 can be somewhat resource intensive at times. Though it would probably still be a good idea to install some upgraded Memmory Modules when you are able to do so.

My W7 Laptop has 4GB of RAM and my Desktop W7 machine has 6GB of RAM and both perform very well for what I use them for.

Any further issues remaining? If not we will clean up the tools used during the course of the Malware Removal process and I will provides some advice about online safety etc.

2011-07-25, 16:10
As the machine is still working quickly, I think we are done! Thank much. When you can, please advise as to how I can safely remove the tools.

Thanks much.

2011-07-25, 16:20
Strange. After working for about 15 minutes today, the PC returned to its slow ways. Very puzzling and frustrating. Any ideas? Thanks again!

2011-07-25, 18:31
Hi. :)

Strange. After working for about 15 minutes today, the PC returned to its slow ways. Very puzzling and frustrating. Any ideas? Thanks again!
Well it not Malware related as far as I can tell so you could try turning off some unnecessary Windows 7 features as follows...

Windows Features - Turn On or Off (http://www.sevenforums.com/tutorials/5023-windows-features-turn-off.html)

A list about such can be found here (http://www.bleepingcomputer.com/tutorials/tutorial134.html), even though says for Vista it is still compatible. <-- Scroll down to Windows Vista Feature List

2011-07-25, 19:08
Thanks again. It doesn't appear that's the problem, and as you said, it's likely not malware either!

I may have to put the old computer out to pasture. Thanks again for having this great site!

2011-07-26, 11:49
Hi. :)

Thanks again. It doesn't appear that's the problem, and as you said, it's likely not malware either!
You're welcome!

I may have to put the old computer out to pasture.
May be a option if the system is unable to support any upgraded memory modules...Though I am wondering if the Acronis backup software is the culprit as that can be quite resource intensive and might be a idea to say launch it manually once per week rather than leaving it to run automatically.

If you wish to try this option create/run the custom batch file below to set the Acronis backup software as manual use only...

Custom Batch File:

Create a Registry Backup with Erunt before creating/running the below batch file...

Via Start(Windows 7 Orb) >> All Programs >> ERUNT >> Right-click on ERUNT and select Run as Administrator >> Follow the prompts.

Open Notepad.
Copy and Paste everything from the Code Box below into Notepad: <-- Start >> Run... type in notepad and select OK

@Echo off
SC Stop AcrSch2Svc
SC Config AcrSch2Svc Start= Demand
Reg Delete "HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /V schedhlp /F
Reg Delete "HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run" /V TrueImageMonitor /F
CMD /C CHKDSK C: |Find /V "Percent" >> "%userprofile%\desktop\checkhd.txt"
Shutdown -R -T 1
Del %0
Go to File >> Save As
Save File name as "Dakeyras.bat" <-- Make sure to include the quotes.
Change Save as Type to All Files and save the file to your Desktop.
It should look similar to this: http://i280.photobucket.com/albums/kk173/Dakeyras_album2/vista-rh.gif
Now right-click on the desktop Dakeyras.bat and select Run as Administrator to run the batch file. It will self-delete when completed and your machine should automatically reboot. If it does not reboot your machine manually.

Note: There will be a notepad file on the desktop afterwards, please post the contents of this in your next reply as this will provide myself with a brief analysis about your machines Hard-Drive current health etc.


Also what exactly are you using LogMeIn for and inform myself if any further issues remaining, thank you.

2011-07-26, 16:43
Thanks again for the response.

I'm a little unsure about that Acronis software myself, and as such, I've given it back to my "PC guy" to remove/fix it. Hopefully that fixes it.

Thanks again for your help, this site is amazing. Feel free to archive this thread.

2011-07-27, 11:45
Hi. :)

I'm a little unsure about that Acronis software myself, and as such, I've given it back to my "PC guy" to remove/fix it. Hopefully that fixes it.
Fair play.

Thanks again for your help, this site is amazing.
You're welcome, it would be prudent to follow the instructions/advice below when able.

Now I have some tasks for your good self to carry out as part of a clean up process and some advice about online safety.

Importance of Regular System Maintenance:

I advice you read both of the below listed topics as this will go a long way to keeping your Computer performing well.

Help! My computer is slow! (http://users.telenet.be/bluepatchy/miekiemoes/slowcomputer.html)

Also so is this:

What to do if your Computer is running slowly (http://www.malwareremoval.com/tutorials/runningslowly.php)

Reset SR Points/Clean up with OTL:

Right-click OTL and select Run as Administrator to start the program.
Copy the lines from the codebox to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

Return to OTL, right-click in the Custom Scans/Fixes window (under the cyan bar) and choose Paste.
Then click the red Run Fix button.
Let the program run unhindered. When finished click on OK and close the log that appears.
Note: I do not need to review the log produced.
Now close all other programs apart from OTL as this step will require a reboot.
On the OTL main screen, depress the CleanUp button.
Say Yes to the prompt and then allow the program to reboot your computer.

The above process will flush old System Restore points and create a new clean one. It should also clean up and remove the vast majority of scanners used and logs created etc.

Any left over merely delete yourself and empty the Recycle Bin.

Now some advice for on-line safety:

Malwarebyte's Anti-Malware:

This is a excellent application and I advise you keep this installed. Check for updates and run a scan at least once per week.

Other installed security software:

Your presently installed security application, Microsoft Security Essentials automatically checks for updates and downloads/installs them with every system reboot and or periodically if the machine is left running providing a internet connection is active.

I advise you also run a complete scan with this also at least once per week.


Emergency Recovery Utility NT, I advice you keep this installed as a means to keep a complete backup of your registry and restore it when needed.

Myself I would actually create a new back up once per week as this along with System Restore may prove to be invaluable if something unforeseen occurs!

Keep your system updated:

Microsoft releases patches for Windows and other products regularly:

Click on Start(Windows 7 Orb) >> All Programs >> Windows Update.
In the navigation pane, click Check for updates.
After Windows Update has finished checking for updates, click View available updates.
Click to select the check box for any found, then click Install.
When completed Reboot(restart) your computer if not prompted to do so.
Be careful when opening attachments and downloading files:

Never open email attachments, not even if they are from someone you know. If you need to open them, scan them with your antivirus program before opening.
Never open emails from unknown senders.
Beware of emails that warn about viruses that are spreading, especially those from antivirus vendors. These email addresses can be easily spoofed. Check the antivirus vendor websites to be sure.
Be careful of what you download. Only download files from known sources. Also, avoid cracked programs. If you need a particular program that costs too much for you, try finding free alternatives on Sourceforge (http://sourceforge.net/) or Pricelessware (http://www.pricelesswarehome.org/).

Stop malicious scripts:

Windows by default allow scripts (which is VBScript and JavaScript) to run and some of these scripts are malicious. Use Noscript (http://www.symantec.com/avcenter/noscript.exe) by Symantec or Script Defender (http://www.analogx.com/contents/download/system/sdefend.htm) by AnalogX to handle these scripts.

Avoid Peer to Peer software:

P2P may be a great way to get lots of seemingly freeware, but it is a great way to get infected as well. There's no way to tell if the file being shared is infected. Worse still, some worms spread via P2P networks, infecting you as well. My advice is avoid these types of software applications.

Hosts File:

A Hosts file is like a phone book. You look up someone's name in the phone book before calling him/her. Similarly, your computer will look up the website's IP address before you can view the website.

Hosts file will replace your current Hosts file with another one containing well-known advertisement sites, spyware sites and other bad sites. This new Hosts file will protect you by re-directing these bad sites to

Here are some Hosts files:

MVPS Hosts File (http://www.mvps.org/winhelp2002/hosts.htm)
hpHosts (http://hosts-file.net/?s=Download)
Only use one of the above!

Install WinPatrol:

WinPatrol alerts you about possible system hijacks, malware attacks and critical changes made to your computer without your permission.

Download it from here (http://www.winpatrol.com/download.html).

You can find information about how WinPatrol works here (http://www.winpatrol.com/features.html).


This is a very helpful/useful set of advice from Microsoft: Microsoft Safety & Security Center (http://www.microsoft.com/security/default.aspx)

Any questions? Feel free to ask, if not stay safe!

2011-07-29, 12:50
Since this issue appears to be resolved ... this Topic has been closed. Glad I could help.

Note: If it has been three days or more since your last post, and the helper assisting you posted a response to that post to which you did not reply, your topic will not be reopened. At that point, if you still require help, please start a new topic and include a fresh set of DDS logs and a link to your previous thread.

If it has been less than three days since your last response and you need the thread re-opened, please send me or your helper a private message (pm). A valid, working link to the closed topic is required.