Following All Steps To Clean A Slow Computer

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by firstphantom, Feb 13, 2017.

  1. firstphantom

    firstphantom Private E-2

    Hello all,
    I am trying to clean a slow running computer and following the steps given here. Attached is the logfile from the first step of running AdwCleaner. Please let me know if there is anything else I can provide. Thank you in advance. If I am supposed to complete all steps before posting any log files please let me know and I will do that.
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please complete all of the instructions in the Read & Run Me First sticky (pinned) thread and when finished, attach the rest of the requested logs.
     
  3. firstphantom

    firstphantom Private E-2

    Attached are the remaining files. Thanks much.
     

    Attached Files:

  4. firstphantom

    firstphantom Private E-2

    I stopped at Step 4 and attached the remaining logs. Computer still runs very slow. I don't want to run anything further before hearing back so please let me know if I need to do anything else. In the meantime Malwarebytes still runs each time I power up and I just click Quit in case that is not supposed to be running. Thanks.
     
  5. firstphantom

    firstphantom Private E-2

    After completing all steps I also now see I have desktop.ini on my desktop. Should I leave this as is until someone reviews my attached log files or can I take steps to hide this icon? Thanks for any help you can offer.
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    Your log from MGtools is very incomplete. Did you wait for it to tell you it was finished before you attached the log? Or did you have a problem running it?

    I'm not seeing any real issues in your logs thus far. Just some minor junkware.

    This normal and you see it now because we enabled viewing of hidden system files.
     
  7. firstphantom

    firstphantom Private E-2

    Thanks chaslang, your time is greatly appreciated. I apologize for not allowing MGTools to complete. I saw the following messages and assumed incorrectly the job was done:

    GRK64.bat - 02/28/2016 Version 0.71

    NOTE: Ignore any error messages about not finding registry keys!
    Just wait for the program to finish running!!

    64 bit Windows OS found
    The operation completed successfully.


    Now I allowed the job to continue until I saw the message telling me to hit Enter to continue. Attached is the log from the latest running. If things still look normal, if you can offer any instructions on how to remove junkware that would be great. Otherwise I will assume I have too much on my hard drive and that is what is causing slow processing.

    Cheers,
    firstphantom
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. First big problem and likely the cause of your slow PC is that you have multiple antivirus programs running. I see both Avast Antivirus and Commtouch AntiVirus5 You need to uninstall one of these immediately and then reboot and see how things are working.

    I also suggest uninstalling NortonPCCheckup
     
  9. firstphantom

    firstphantom Private E-2

    The only antivirus I installed is Avast Antivirus as recommended by MajorGeeks, so how Commtouch AntiVirus5 got on here I don't know. I also did not purposely install NortonPCCheckup and would like to remove that as well.

    When I go to Control Panel/Uninstall a Program, I do not see either program. When I Start Task Manager I do not see Commtouch or NortonPCCheckup listed under Processes or Services. I would like to remove both and will appreciate if you can direct me to instructions on how.

    Under Processes I do see:

    vseamps.exe - AVSDK5 Active Protection Singleton Service

    vsedsps.exe - AVSDK5 Dispatcher/notification Server

    and

    ccSvcHst.exe *32 - Symantec Service Framework

    ccSvcHst.exe *32 - Symantec Service Framework

    Are these the two programs disguising their names?

    Thank you in advance for any advice you can provide on both removals.
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay we will work on removing this programs. But first I will need you to run another scan tool to collect more information so that we can properly remove them.

    Please download the latest version of FRST the below link.

    Farbar Recovery Scan Tool and save it to your Desktop.
    • See the download links under this icon [​IMG]
    • Double-click to run it. When the tool opens click Yes to disclaimer.
    • Press Scan button.
    • It will make a log (FRST.txt) in the same directory the tool is run. Please attach it to your next reply.
    • The first time the tool is run, it makes also another log (Addition.txt). Please attach it to your reply.
     
  11. firstphantom

    firstphantom Private E-2

    The link you provided was to the 32 bit version and my system said I need the 64 bit version so I downloaded that from majorgeeks and ran that. The resulting files are attached here. Thanks...
     

    Attached Files:

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay Let's first run a small script with FRST to see if we can unhide the Commtouch AntiVirus5 program which is showing as company named Cyren Inc in your logs and also it is the cause of services you notice above. If we are successful at un-hiding it, it may then be possible to uninstall it.

    Download the attached fixlist.txt file found at the bottom of this message and save fixlist.txt on your Desktop. Make sure you save it as a txt file.
    • You should now have both fixlist.txt and FRST64.exe on your Desktop.
    • Now I want you to disconnect your PC connection to the internet by unplugging the cable ( if it is wireless then temporarily shutdown the wireless network ).
    • Run FRST64.exe by right clicking on it and selecting Run As Adminstrator
    • Click the Fix button just once and wait.
    • Your computer should reboot after the fix runs.
    • Reconnect your internet connection after reboot so you can come back here to continue.
    • The tool will make a log on the Desktop (Fixlog.txt) please attach this new log to your next reply (attach or paste)

    Was it able to unhide the installation? If yes, make sure that you have attempted to uninstall it. Either way let me know the results and then I will post the next fix that we will run with FRST again.
     

    Attached Files:

  13. firstphantom

    firstphantom Private E-2

    This worked exactly as you laid out. After the fix and reboot, fixlist.txt disappeared from the Desktop and was replaced by Fixlog.txt. Also this appeared under Control Panel/Uninstall a Program:

    Name: AVSDK5
    Publisher: CYREN Inc.
    Installed on 1/9/15
    Size: 10.5MB
    Version: 5.4.12

    Then the uninstall worked. Attached is the log file produced.
     

    Attached Files:

  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay let's continue with removal of Cyren ( some of this will be redundant ) and Norton.

    Download the attached fixlist.txt file found at the bottom of this message and save fixlist.txt on your Desktop. Make sure you save it as a txt file.
    • You should now have both fixlist.txt and FRST64.exe on your Desktop.
    • Now I want you to disconnect your PC connection to the internet by unplugging the cable ( if it is wireless then temporarily shutdown the wireless network ).
    • Run FRST64.exe by right clicking on it and selecting Run As Adminstrator
    • Click the Fix button just once and wait.
    • Your computer should reboot after the fix runs.
    • Reconnect your internet connection after reboot so you can come back here to continue.
    • The tool will make a log on the Desktop (Fixlog.txt) please attach this new log to your next reply (attach or paste)
    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • Fixlog.txt
    • C:\MGlogs.zip
    How is your PC running?
     

    Attached Files:

  15. firstphantom

    firstphantom Private E-2

    Thank you chaslang. Having run through all the steps you gave my laptop is running smoothly now. I have attached the 2 files you requested. My only other question concerns startup. It takes close to 7 minutes from the time I first boot up for my hard drive light to stop being on solid. I have 83 services and 72 processes running once startup completes. Is there a way to figure out which ones are necessary and which I can eliminate? Any help in that area will also be appreciated. Otherwise thank you again for all your help!
     

    Attached Files:

  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Your logs look fine now.
    You can discuss things like this in the Software Forum. However I will say it is quite typical for a laptop and for the software apps you have installed. You have lots of processes/services to support the hardware on the laptop and you have a lot of Apple related stuff running too.

    Since you are not having anymore malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    3. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If you are running Win 8, Win 7, Vista, Windows XP or Windows ME, do the below to flush restore points:
      • Refer to the instructions for your Windows version in this link: Disable And Enable System Restore
      • For Windows 8 and 8.1 system restore see this link: Win 8 System Restore - How to enable/disable
      • What we want you to do is to first disable System Restore to flush restore points some of which could be infected.
      • Then we want you to Enable System Restore to create a new clean Restore Point.
    6. After doing the above, you should work thru the below link:
     
  17. firstphantom

    firstphantom Private E-2

    Thank you. I ran all the above steps. I still will need the steps to reverse what I needed to do at the beginning. For instance my User Account Control Settings are still set to Never Notify about changes to the computer and desktop.ini is still visible. Is there one last step of steps to restore back to where I began?
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you run MGclean.bat? Did you use Right Click and select Run As Administrator to run it? Did it seem to run properly? It should have re-hid the system files. For UAC you can just follow the same steps you used previously but this time set it back to default. Very likely there is even a warning in you system tray about UAC and you can click on this warning to set it back to defaults.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds