Need help badly

My computer starts fine and then after about 15- 20 minutes or so, it gets EXTREMELY slow. It sounds like the processor or whatever is racing and nothing works. I scanned with MBAM and avast and cleaned what was there. This worked during a similar incident about 6 months ago.

This accomplished nothing this time.

The avast scan did show some things that were password protected but wouldn’t allow me to do anything to them. Any suggestions? My instinct is telling me that several 12 gauge slugs fired into the computer may solve the problem.

But seriously, I am in pretty desperate shape right now. Any help would be greatly appreciated. Thanks.

Hi,

Please download AdwCleaner by Xplode and save to your Desktop.

Double click on AdwCleaner.exe to run the tool.

[*]Click on the Scan button.
[*]After the scan has finished click on the Clean button.

Press OK when asked to close all programs and follow the onscreen prompts.
Press OK again to allow AdwCleaner to restart the computer and complete the removal process.

[*]After rebooting, a logfile report (AdwCleaner[S0].txt) will open automatically.
[*]Post logfile will also be saved in the C:\AdwCleaner folder.

Then…

Please download aswMBR and save it to your desktop.

Double click aswMBR.exe to start the tool.

[*]Select Yes if prompted to download the Avast database.
[*]Click Scan
[*]Upon completion of the scan ( Scan finished successfully ) click Save log and save it to your desktop, and post that log in your next reply for review.
Note: do NOT attempt any Fix yet.

Then…

Please download Farbar Recovery Scan Tool by Farbar and save it to your desktop.

Note: You need to run the version compatibale with your system. If you are not sure which version applies to your system download both of them and try to run them.
Only one of them will run on your system, that will be the right version.

[*]Double-click to run it. When the tool opens click Yes to disclaimer.
[*]Under Optional Scan ensure “List BCD” and “Driver MD5” are ticked.
[*]Press Scan button.
[*]It will make a log (FRST.txt) in the same directory the tool is run. Please attach it to your reply.
[*]The first time the tool is run, it makes also another log (Addition.txt). Please attach it to your reply.

I scanned with MBAM and avast and cleaned what was there
was anything detected? ..... if so attach logs
The avast scan did show some things that were password protected but wouldn't allow me to do anything to them.
not detections.... just a scan error message avast is a antivirus program and will only take action on infected files

follow TwinHeadedEagles instructions…

These are the logs:

What am I doing wrong? I cant post more than 1 at a time. Overwhelmed with everything here.

.

Anyone?

patient … removers are volunteers and spend there free time helping and are not online 24/7

Understood Pondus. Thanks for the heads up.

First thing: You have two antivirus programs installed, that is bad and may lead your system to strange behaving. Download this tool to remove Avira from your computer

http://dlpro.antivir.com/package/removaltool/win32/en/removaltool-win32-en.exe

Then…

1. Open notepad and copy/paste the text present inside the code box below.
To do this highlight the contents of the box and right click on it. Paste this into the open notepad.
NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to the operating system

URLSearchHook: HKCU - UrlSearchHook Class - {00000000-6E41-4FD3-8538-502F5495E5FC} - C:\Program Files\Ask.com\GenericAskToolbar.dll No File
C:\Program Files\Ask.com
cmd: netsh winsock reset
cmd: ipconfig /flushdns
hosts:
CHR HKLM\...\Chrome\Extension: [banjjklfojcdbofbhbgiedekefohoaff] - C:\Documents and Settings\bob oliveri\Local Settings\Application Data\CRE\banjjklfojcdbofbhbgiedekefohoaff.crx
C:\Documents and Settings\bob oliveri\Local Settings\Application Data\CRE\banjjklfojcdbofbhbgiedekefohoaff.crx
C:\Documents and Settings\Administrator\hpothb07.dat
C:\Documents and Settings\Administrator.UPSTAIRS\hpothb07.dat
C:\Documents and Settings\Administrator.UPSTAIRS.000\hpothb07.dat
C:\Documents and Settings\Administrator.UPSTAIRS.001\hpothb07.dat
C:\Documents and Settings\All Users\hpothb07.dat
C:\Documents and Settings\bob oliveri\hpothb07.dat
C:\Documents and Settings\bob oliveri\test.bat
C:\Documents and Settings\Default User\hpothb07.dat
C:\Documents and Settings\LocalService\hpothb07.dat
C:\Documents and Settings\NetworkService\hpothb07.dat
C:\Windows\Tasks\At1.job
C:\Windows\Tasks\At10.job
C:\Windows\Tasks\At11.job
C:\Windows\Tasks\At12.job
C:\Windows\Tasks\At13.job
C:\Windows\Tasks\At14.job
C:\Windows\Tasks\At15.job
C:\Windows\Tasks\At16.job
C:\Windows\Tasks\At17.job
C:\Windows\Tasks\At18.job
C:\Windows\Tasks\At19.job
C:\Windows\Tasks\At2.job
C:\Windows\Tasks\At20.job
C:\Windows\Tasks\At21.job
C:\Windows\Tasks\At22.job
C:\Windows\Tasks\At23.job
C:\Windows\Tasks\At24.job
C:\Windows\Tasks\At25.job
C:\Windows\Tasks\At26.job
C:\Windows\Tasks\At27.job
C:\Windows\Tasks\At28.job
C:\Windows\Tasks\At29.job
C:\Windows\Tasks\At3.job
C:\Windows\Tasks\At30.job
C:\Windows\Tasks\At31.job
C:\Windows\Tasks\At32.job
C:\Windows\Tasks\At33.job
C:\Windows\Tasks\At34.job
C:\Windows\Tasks\At35.job
C:\Windows\Tasks\At36.job
C:\Windows\Tasks\At37.job
C:\Windows\Tasks\At38.job
C:\Windows\Tasks\At39.job
C:\Windows\Tasks\At4.job
C:\Windows\Tasks\At40.job
C:\Windows\Tasks\At41.job
C:\Windows\Tasks\At42.job
C:\Windows\Tasks\At43.job
C:\Windows\Tasks\At44.job
C:\Windows\Tasks\At45.job
C:\Windows\Tasks\At46.job
C:\Windows\Tasks\At47.job
C:\Windows\Tasks\At48.job
C:\Windows\Tasks\At5.job
C:\Windows\Tasks\At6.job
C:\Windows\Tasks\At7.job
C:\Windows\Tasks\At8.job
C:\Windows\Tasks\At9.job
C:\Documents and Settings\bob oliveri\Local Settings\temp
C:\Documents and Settings\All Users\Application Data\24dCrlQF.exe
AlternateDataStreams: C:\Documents and Settings\All Users\Application Data\TEMP:13E0F5E5
AlternateDataStreams: C:\Documents and Settings\All Users\Application Data\TEMP:205F1AE3
AlternateDataStreams: C:\Documents and Settings\All Users\Application Data\TEMP:9D5F6B57
AlternateDataStreams: C:\Documents and Settings\All Users\Application Data\TEMP:A11F741D
AlternateDataStreams: C:\Documents and Settings\All Users\Application Data\TEMP:C46995DA
AlternateDataStreams: C:\Documents and Settings\All Users\Application Data\TEMP:D4F1F66F

2. Save notepad as fixlist.txt to your Desktop.
NOTE: => It’s important that both files, FRST and fixlist.txt are in the same location or the fix will not work.

3. Run FRST/FRST64 and press the Fix button just once and wait.
If the tool needed a restart please make sure you let the system to restart normally and let the tool completes its run after restart.

The tool will make a log on the Desktop (Fixlog.txt). Please attach it to your reply.
Note: If the tool warned you about the outdated version please download and run the updated version.

Then…

  1. Please download ComboFix by sUBs from here and save it to your Desktop.
    If you are unsure how ComboFix works please read this guide carefully.
    note: ComboFix must be downloaded to your Desktop.

  1. Temporarily disable your AntiVirus program, usually via a right click on the System Tray icon. They may interfere with Combofix.
    If you are unsure how to do this please read this or this Instruction.

Instructions how to disable avast:

[*]Right click on the avast! system tray icon (
http://www.mcshield.net/pg/images/avast5.png
) in the lower right corner of the screen and scroll up to avast! shield controls;
[*]In the menu that appears, choose Disable Permanently. When you are prompted to turn off security, click Yes.

Note: Do not forget to turn back on this option after the cleaning by choosing avast! shield controls > Enable all shield options.


  1. Run ComboFix. Click on I Agree!

ComboFix will check if there is a newer version of ComboFix available.
Click Yes if prompted to download.
ComboFix will display DISCLAIMER OF WARRANTY ON SOFTWARE.
Click Yes to allow ComboFix to continue.
If Recovery Console is not installed, ComboFix will offer download & installation.
Click Yes to allow ComboFix to install Recovery Console.
Note:Do not mouse-click Combofix’s window while it is running.
If you see a message like “Illegal operation attempted on a registry key that has been marked for deletion” just restart computer once more.


  1. When the tool is finished, it will produce a log report for you. (typical location: C:[b]ComboFix.txt[/b] )
    Attach log reports ( ComboFix.txt) back to topic.

I can’t get rid or turn off Avira. The program you gave me only scanned. Combofix is now waiting for me tto turn it off. How do I do that? I’m in safe mode.

Also, FRST says it cant find fixit.txt. It’s on the desktop.

First we will remove Avira. Do you have it in Control Panel → Add or Remove Programs

No, I checked but it isn’t there. Combo fix says it’s active and it’s still in 'program files, but not in Add/remove. Avast is off. Could just be a glitch?

Do you know how to restart into Safe Mode?

Yes, I’m there now. Will this affect Combofix which has that warning up?

We’ll run ComboFix later, first to remove Avira

Follow this instruction, starting from Step 2.

http://www.avira.com/en/support-for-home-knowledgebase-detail/kbid/902

After you delete Avira, procede with FRST, and with ComboFix at the end.

File for FRST must be named exactly fixlist.txt

Ok. I completed that and deleted all the Avira registry keys.

Good, procede with FRST, and ComboFix