C drive busy after uninstalling bitdefender

Discussion in 'Malware Help (A Specialist Will Reply)' started by Raphee, Jun 1, 2015.

  1. Raphee

    Raphee Private First Class

    I uninstalled BD a fortnight ago using IObit which I installed from MajorGeeks. BD has left behind BD Safepay and BD antivirus plus. I suspect these remnants are slowing down my laptop, Windows 7 64 bit. When I turn the laptop on the C drive may remain busy for up to 45 min or one hour. Effectively that forces me to start work late, and wait for the hard drive to go quiet.
    I ran malware bytes. There were a lot of PUP conduit. Removed those. But the problem remained. I then did the steps mentioned on MG in Run and Read thread. There has been a slight improvement but not much.

    I am attaching the logs for you to see and advise me. Thanks.
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    This is not a malware issue but I will post a small fix to be rid of what Bitdefender remnants I do see. :)

    Download and run OTM.

    Download OTM by Old Timer and save it to your Desktop.

    Code:
    :Files
    C:\ProgramData\1430197597.bdinstall.bin
    C:\ProgramData\1430198863.bdinstall.bin
    C:\ProgramData\Bitdefender
    C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Bitdefender
    
    :reg
    [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
    "Bitdefender Wallet Agent"=-
    "Bitdefender Wallet"=-
    "Bitdefender Wallet Application Agent"=-
    
    :Commands
    [emptytemp]
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar) and choose Paste.
    • Push the large http://farm3.static.flickr.com/2782/4174320048_f01c448b32_o.png button.
    • OTM may ask to reboot the machine. Please do so if asked.
    • Copy everything in the Results window (under the green bar), and paste it into a text file to ATTACH into your next reply.

    NOTE: If you are unable to copy/paste from this window (as will be the case if the machine was rebooted), open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTM\MovedFiles folder, and open the newest .log file present, and attach the contents of that document back here in your next post.




    http://imageshack.us/a/img841/7292/thisisujrt.gif Please download Junkware Removal Tool to your desktop.
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.


    Run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista, Windows7 or Win8) Then attach the new C:\MGlogs.zip file that will be created by running this.
     
  3. Raphee

    Raphee Private First Class

    Thanks Kestrel, you're super fast and super prompt as always.

    I've run the software and am attaching the log files.

    PS: Just for your info, after running OTM the log file was already open on desktop. I saved the same and am sending. Perhaps this might help with other Win 7 users. Dunno.
     

    Attached Files:

  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    No problem. :)

    Delete this:
    C:\ProgramData\Bitdefender

    Ready for final steps?
     
  5. Raphee

    Raphee Private First Class

    Unable to delete c/programdata/bitdefender.

    Get a message saying the program is open and cannot be deleted.
     
  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You may have to take this up in the software forum... we'll try this first...

    SystemLook

    Please download SystemLook from one of the links below appropriate for your operating system and save it to your Desktop.
    Download 32 Bit
    Download 64 Bit

    • Double-click SystemLook.exe to run it.
    • Copy the content of the following codebox into the main textfield:
      Code:
      :filefind
      Bitdefender
      :regfind
      Bitdefender
    • Click the Look button to start the scan.
    • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
    Note: The log can also be found on your Desktop entitled SystemLook.txt
     
  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Also delete this if it exists....

    C:\Program Files\Bitdefender
     
  8. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    @Kes

    Check your PM's please.
     
  9. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Yes, Dr M what I tried to fix is still showing in the logs. I am hoping Systemlook finds more. Will try for one more sweep and then user will have to go to software for support as this is not a malware issue. :)
     
  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

  11. Raphee

    Raphee Private First Class

    Kestrel, System look log is attached.

    C:/Program files/Bit defender exists. I tried to delete it. But I get a message saying I need permission from the Administrator to delete. As far as I know I do have administration rights on my laptop. (its for personal use.) Unless I am doing something wrong.

    I haven't yet tried the uninstall tool. I thought I'd send you the log first, and wait for your reply.

    I've been away from my laptop and could not keep up with your pace. Thanks.
     

    Attached Files:

  12. Raphee

    Raphee Private First Class

    Sorry just realized I had downloaded and scanned with System Look 32 bit.

    I've run the scan again using the 64 bit tool and am attaching the log file.
     

    Attached Files:

  13. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Try the uninstall tool, there's just so many remnants it might be quicker.
    Once you have run the tool, re run Systemlook 64bit! the same way as before and attach log.
     
  14. Raphee

    Raphee Private First Class

    Which version do I run. Or will anyone do the job? Theres no guidance on the BD site.
     
  15. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Run the AntiVirus Plus please.
     
  16. Raphee

    Raphee Private First Class

    Ran uninstall tool for Bitdef, followed by System Look. I've attached the log for you. Thanks.
     

    Attached Files:

  17. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    OK as I have said before, this is not a malware problem, and I don't want others who log into the forum to think that it is, I suggest you make a post in software about this, you can attach the systemlook log for them and explain that antivirus registry remnants remain. :) Best of luck!

    Remains:

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.

    7. After doing the above, you should work thru the below link:
     
  18. Raphee

    Raphee Private First Class

    Doing it. Thanks Kestrel for all the time and assistance.
     
  19. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You are most welcome! :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds