Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Multiple instances of Chrome slowing down my PC


  • This topic is locked This topic is locked
15 replies to this topic

#1 m1eyp

m1eyp

  • Members
  • 66 posts
  • OFFLINE
  •  
  • Local time:03:07 PM

Posted 29 July 2017 - 06:18 AM

My PC slows right down and sometimes hangs completely for up to 10 minutes.  When this happens, I go to the Task Manager (which itself takes up to a minute to appear after pressing CTRL+ALT+DELETE) and see 6 to 10 instances of Chrome running.  I kill them all, and start again, then my PC is OK again for a while.  But at some point, the Chrome instances will stack up again.  

 

When I look in Task Manager, I can see that these processes are growing in memory size very quickly, by the second.

 

I've read online that this is a virus/malware, and one that the Anti-virus/malware software doesn't detect.  I've also read a glowing recommendation for Bleeping Computer in terms of getting help to fix this - so here I am!  Thanks in anticipation.

 

(I've attached a screengrab of my Task Manager taken just now.  I've already had to go through one process of killing instance of Chrome this morning.  The PC is running OK at the moment, but it will only be a matter of time before I have to go to the Task Manager and kill off all the Chrome again).

Attached Files


Edited by hamluis, 29 July 2017 - 06:56 AM.
Moved from Win 7 to Am I Infected - Hamluis.


BC AdBot (Login to Remove)

 


#2 buddy215

buddy215

  • Moderator
  • 13,411 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:West Tennessee
  • Local time:09:07 AM

Posted 29 July 2017 - 07:35 AM

Chrome starts a new process for each opened tab. There may be other issues such as adware or malware.

Also see info in this link...​Stop Chrome from Running In the Background After You Close It

 

Use the programs below to clean, remove adware and remove malware.

 

Use CCleaner to remove Temporary files, program caches, cookies, logs, etc. Use the Default settings. No need to use the

Registry Cleaning Tool...risky. Pay close attention while installing and UNcheck offers of toolbars....especially Google.

After install, open CCleaner and run by clicking on the Run Cleaner button in the bottom right corner.

CCleaner - PC Optimization and Cleaning - Free Download

 

  • download Malwarebytes to your desktop.
  • Double-click mb3-setup-1878.1878-3.0.6.1469.exe and follow the prompts to install the program.
  • Then click Finish.
  • Once the program has fully updated, select Scan Now on the Dashboard. Or select the Threat Scan from the Scan menu.
  • If another update of the definitions is available, it will be implemented before the rest of the scanning procedure.
  • When the scan is complete, make sure that all Threats are selected, and click Remove Selected.
  • Restart your computer when prompted to do so.
  • The Scan log is available throughout History ->Application logs. Please post it contents in your next reply.

Download AdwCleaner by Xplode onto your desktop.

  • Close all open programs and internet browsers.
  • Double click on adwcleaner.exe to run the tool.
  • Click on Scan button.
  • When the scan has finished click on Clean button.
  • Your computer will be rebooted automatically. A text file will open after the restart.
  • Please post the contents of that logfile with your next reply.
  • You can find the logfile at C:\AdwCleaner[S1].txt as well.
  • download Junkware Removal Tool to your desktop.
  • Shut down your protection software now to avoid potential conflicts.
  • Run the tool by double-clicking it. If you are using Windows Vista, 7, or 8; instead of double-clicking, right-mouse click JRT.exe and select "Run as Administrator".
  • The tool will open and start scanning your system.
  • Please be patient as this can take a while to complete depending on your system's specifications.
  • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
  • Post the contents of JRT.txt into your next message

Edited by buddy215, 30 July 2017 - 05:38 AM.

“Every atom in your body came from a star that exploded and the atoms in your left hand probably came from a different star than your right hand. It really is the most poetic thing I know about physics...you are all stardust.”Lawrence M. Krauss
A 1792 U.S. penny, designed in part by Thomas Jefferson and George Washington, reads “Liberty Parent of Science & Industry.”

#3 m1eyp

m1eyp
  • Topic Starter

  • Members
  • 66 posts
  • OFFLINE
  •  
  • Local time:03:07 PM

Posted 31 July 2017 - 05:30 AM

Thank you so much for this advice.  I am working through it right now.  I will post the logs as requested in subsequent replies.



#4 m1eyp

m1eyp
  • Topic Starter

  • Members
  • 66 posts
  • OFFLINE
  •  
  • Local time:03:07 PM

Posted 31 July 2017 - 05:48 AM

Malwarebytes log:

 

Malwarebytes
www.malwarebytes.com
 
-Log Details-
Scan Date: 7/31/17
Scan Time: 11:19 AM
Log File: 
Administrator: Yes
 
-Software Information-
Version: 3.1.2.1733
Components Version: 1.0.139
Update Package Version: 1.0.2472
License: Trial
 
-System Information-
OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: TomRead-PC\Tom Read
 
-Scan Summary-
Scan Type: Threat Scan
Result: Completed
Objects Scanned: 328180
Threats Detected: 19
Threats Quarantined: 18
Time Elapsed: 14 min, 53 sec
 
-Scan Options-
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled
 
-Scan Details-
Process: 0
(No malicious items detected)
 
Module: 0
(No malicious items detected)
 
Registry Key: 0
(No malicious items detected)
 
Registry Value: 0
(No malicious items detected)
 
Registry Data: 0
(No malicious items detected)
 
Data Stream: 0
(No malicious items detected)
 
Folder: 1
PUP.Optional.Spigot, C:\USERS\TOM READ\APPDATA\LOCAL\d3c9ef70-c3b3-4bdc-a34a-3779e4f15958, Quarantined, [620], [318193],1.0.2472
 
File: 18
Adware.DealPly, C:\USERS\TOM READ\APPDATA\ROAMING\SETUP67248.EXE, Quarantined, [445], [323141],1.0.2472
Adware.DealPly, C:\USERS\TOM READ\APPDATA\ROAMING\SETUP2802.EXE, Quarantined, [445], [323141],1.0.2472
PUP.Optional.Ilivid, C:\USERS\TOM READ\DOCUMENTS\DOWNLOADS\ILIVIDSETUPV1.EXE, Quarantined, [3098], [56018],1.0.2472
PUP.Optional.SofTonic, C:\USERS\TOM READ\DOCUMENTS\DOWNLOADS\SOFTONICDOWNLOADER_FOR_WAVELAB.EXE, Quarantined, [3174], [8262],1.0.2472
PUP.Optional.ClientConnect, C:\USERS\TOM READ\DOCUMENTS\DOWNLOADS\SETUP_TSV35E68V.EXE, Quarantined, [1335], [53767],1.0.2472
PUP.Optional.Conduit, C:\USERS\TOM READ\DOCUMENTS\DOWNLOADS\SETUP.EXE, Quarantined, [551], [111936],1.0.2472
PUP.Optional.RegCleanPro, C:\USERS\TOM READ\DOCUMENTS\DOWNLOADS\RCP_DCOMNEW_SEC_300.EXE, Quarantined, [1402], [3723],1.0.2472
PUP.Optional.InffinityInternet, C:\USERS\TOM READ\DOCUMENTS\DOWNLOADS\SONY_VEGAS_PRO.EXE, Quarantined, [15520], [301062],1.0.2472
PUP.Optional.Yontoo, C:\USERS\TOM READ\DOWNLOADS\FLVPLAYER-CHROME.EXE, Quarantined, [39], [96485],1.0.2472
PUP.Optional.Yontoo, C:\PROGRAMDATA\NTUSER.POL, Removal Failed, [39], [-1],0.0.0
PUP.Optional.Yontoo, C:\WINDOWS\SYSTEM32\GROUPPOLICY\MACHINE\REGISTRY.POL, Quarantined, [39], [-1],0.0.0
PUP.Optional.DsiLoad, C:\USERS\TOM READ\APPDATA\LOCAL\DSISETUP20992432.EXE, Quarantined, [5907], [68115],1.0.2472
PUP.Optional.DomaIQ, C:\USERS\TOM READ\DOWNLOADS\PLAYER SETUP.EXE, Quarantined, [1581], [301240],1.0.2472
PUP.Optional.SpeedyPC, C:\USERS\TOM READ\DOWNLOADS\SPEEDYPC_ERROR_FIX(1).EXE, Quarantined, [849], [396732],1.0.2472
PUP.Optional.DsiLoad, C:\USERS\TOM READ\APPDATA\LOCAL\DSISETUP7690692.EXE, Quarantined, [5907], [68115],1.0.2472
PUP.Optional.SpeedyPC, C:\USERS\TOM READ\DOWNLOADS\SPEEDYPC_ERROR_FIX.EXE, Quarantined, [849], [396732],1.0.2472
PUP.Optional.IBryte, C:\USERS\TOM READ\APPDATA\LOCAL\D3C9EF70-C3B3-4BDC-A34A-3779E4F15958\SYSAD.EXE, Quarantined, [3170], [75986],1.0.2472
PUP.Optional.SwiftBrowse, C:\USERS\TOM READ\DOWNLOADS\ZIPPER_SETUP.EXE, Quarantined, [5326], [59757],1.0.2472
 
Physical Sector: 0
(No malicious items detected)
 
 
(end)


#5 m1eyp

m1eyp
  • Topic Starter

  • Members
  • 66 posts
  • OFFLINE
  •  
  • Local time:03:07 PM

Posted 31 July 2017 - 05:55 AM

Adw log:

 

# AdwCleaner 7.0.0.0 - Logfile created on Mon Jul 31 10:51:26 2017
# Updated on 2017/17/07 by Malwarebytes 
# Running on Windows 7 Home Premium (X64)
# Mode: clean
 
***** [ Services ] *****
 
No malicious services deleted.
 
***** [ Folders ] *****
 
No malicious folders deleted.
 
***** [ Files ] *****
 
No malicious files deleted.
 
***** [ DLL ] *****
 
No malicious DLLs cleaned.
 
***** [ WMI ] *****
 
No malicious WMI cleaned.
 
***** [ Shortcuts ] *****
 
No malicious shortcuts cleaned.
 
***** [ Tasks ] *****
 
No malicious tasks deleted.
 
***** [ Registry ] *****
 
No malicious registry entries deleted.
 
***** [ Firefox (and derivatives) ] *****
 
SearchProvider deleted: astromenda.com - Astromenda
 
 
***** [ Chromium (and derivatives) ] *****
 
SearchProvider deleted: Ask Jeeves - uk.ask.com
 
 
*************************
 
::Tracing keys deleted
::Winsock settings cleared
::Additional Actions: 0
 
 
 
*************************
 
C:/AdwCleaner/AdwCleaner[C0].txt - [6328 B] - [2016/12/17 10:54:30]
C:/AdwCleaner/AdwCleaner[S0].txt - [6139 B] - [2016/12/17 10:52:55]
C:/AdwCleaner/AdwCleaner[S1].txt - [1266 B] - [2017/7/31 10:51:9]
 
 
########## EOF - C:\AdwCleaner\AdwCleaner[C1].txt ##########


#6 m1eyp

m1eyp
  • Topic Starter

  • Members
  • 66 posts
  • OFFLINE
  •  
  • Local time:03:07 PM

Posted 31 July 2017 - 06:06 AM

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Malwarebytes
Version: 8.1.4 (07.09.2017)
Operating System: Windows 7 Home Premium x64 
Ran by Tom Read (Administrator) on 31/07/2017 at 11:58:07.18
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
 
 
 
 
File System: 34 
 
Successfully deleted: C:\ProgramData\pdfforge (Folder) 
Successfully deleted: C:\Windows\wininit.ini (File) 
Successfully deleted: C:\Users\Tom Read\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0PS72R2M (Temporary Internet Files Folder) 
Successfully deleted: C:\Users\Tom Read\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\32S77E1T (Temporary Internet Files Folder) 
Successfully deleted: C:\Users\Tom Read\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\3ZD46JW2 (Temporary Internet Files Folder) 
Successfully deleted: C:\Users\Tom Read\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\62AXOPQ5 (Temporary Internet Files Folder) 
Successfully deleted: C:\Users\Tom Read\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\9Y69VFZP (Temporary Internet Files Folder) 
Successfully deleted: C:\Users\Tom Read\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\B97Q6LDV (Temporary Internet Files Folder) 
Successfully deleted: C:\Users\Tom Read\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\F58DQ6UG (Temporary Internet Files Folder) 
Successfully deleted: C:\Users\Tom Read\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\FZG8CKJ5 (Temporary Internet Files Folder) 
Successfully deleted: C:\Users\Tom Read\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\J6UCL31N (Temporary Internet Files Folder) 
Successfully deleted: C:\Users\Tom Read\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\J8FI1G4V (Temporary Internet Files Folder) 
Successfully deleted: C:\Users\Tom Read\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LIXMVQOA (Temporary Internet Files Folder) 
Successfully deleted: C:\Users\Tom Read\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\M92FD5LI (Temporary Internet Files Folder) 
Successfully deleted: C:\Users\Tom Read\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RC1KN92G (Temporary Internet Files Folder) 
Successfully deleted: C:\Users\Tom Read\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\UJ6Z9BQN (Temporary Internet Files Folder) 
Successfully deleted: C:\Users\Tom Read\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\V2K3072G (Temporary Internet Files Folder) 
Successfully deleted: C:\Users\Tom Read\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\VJCBHQDQ (Temporary Internet Files Folder) 
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0PS72R2M (Temporary Internet Files Folder) 
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\32S77E1T (Temporary Internet Files Folder) 
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\3ZD46JW2 (Temporary Internet Files Folder) 
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\62AXOPQ5 (Temporary Internet Files Folder) 
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\9Y69VFZP (Temporary Internet Files Folder) 
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\B97Q6LDV (Temporary Internet Files Folder) 
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\F58DQ6UG (Temporary Internet Files Folder) 
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\FZG8CKJ5 (Temporary Internet Files Folder) 
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\J6UCL31N (Temporary Internet Files Folder) 
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\J8FI1G4V (Temporary Internet Files Folder) 
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LIXMVQOA (Temporary Internet Files Folder) 
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\M92FD5LI (Temporary Internet Files Folder) 
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RC1KN92G (Temporary Internet Files Folder) 
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\UJ6Z9BQN (Temporary Internet Files Folder) 
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\V2K3072G (Temporary Internet Files Folder) 
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\VJCBHQDQ (Temporary Internet Files Folder) 
 
 
 
Registry: 0 
 
 
 
 
 
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 31/07/2017 at 12:01:48.48
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~


#7 buddy215

buddy215

  • Moderator
  • 13,411 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:West Tennessee
  • Local time:09:07 AM

Posted 31 July 2017 - 07:13 AM

Got rid of some nasty adware.

 

Eset will take an hour or more to run based on your computer's resources, size of data files and whether it has full use of the computer's resources.

So, plan accordingly.

 

Download and run the FREE online scanner from Free Virus Scan | Online Virus Scan from ESET | ESET

  • Place a checkmark in YES, I accept the Terms of Use, then click Start. Wait for ESET Online Scanner to load its components.
  • Select Enable detection of potentially unwanted applications.
  • Click Advanced Settings, then place a checkmark in the following:
    • Remove found threats
    • Scan archives
    • Scan for potentially unsafe applications
    • Enable Anti-Stealth technology
  • Click Start to begin scanning.
  • ESET Online Scanner will start downloading signatures and scan. Please be patient, as this scan can take quite some time.
  • When the scan is done, click List threats (only available if ESET Online Scanner found something).
  • Click Export, then save the file to your desktop.
  • Click Back, then Finish to exit ESET Online Scanner.
  • download Security Check by glax24 and save the file to the Desktop
  • Run the tool by accepting all the Security prompts
  • when complete the tool will produce a log file C:\SecurityCheck\SecurityCheck.txt and also copy the contents to the Clipboard
  • Simply Paste the log to your reply

“Every atom in your body came from a star that exploded and the atoms in your left hand probably came from a different star than your right hand. It really is the most poetic thing I know about physics...you are all stardust.”Lawrence M. Krauss
A 1792 U.S. penny, designed in part by Thomas Jefferson and George Washington, reads “Liberty Parent of Science & Industry.”

#8 m1eyp

m1eyp
  • Topic Starter

  • Members
  • 66 posts
  • OFFLINE
  •  
  • Local time:03:07 PM

Posted 31 July 2017 - 02:27 PM

ESET Scanner found these:

 

C:\AdwCleaner\quarantine\files\jjplixocjsqxdqnksquttojzawluachb\UpdateProc\bkup.dat VBS/Kryptik.DY trojan
C:\AdwCleaner\quarantine\files\jjplixocjsqxdqnksquttojzawluachb\UpdateProc\UpdateTask.exe a variant of Win32/DealPly.AD potentially unwanted application
C:\DATA\Documents and Settings\All Users\Application Data\Conduit\Multi\CT3282502\UninstallerUI.exe a variant of Win32/Toolbar.Conduit.AR potentially unwanted application
C:\DATA\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\ConduitSearchProtect105.zip Win32/Bagle.gen.zip worm
C:\DATA\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\USTechSupportMyCleanPC.zip Win32/Bagle.gen.zip worm
C:\DATA\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinMuollo1.zip Win32/Bagle.gen.zip worm
C:\DATA\Documents and Settings\All Users\Application Data\Tarma Installer\{ED7702F7-093C-4968-8B84-3CF5D1A3F23D}\_Setupx.dll a variant of Win32/Adware.Yontoo.B application
C:\DATA\Documents and Settings\Liam\Application Data\Mozilla\Firefox\Profiles\38dmks5b.default\extensions\52ffxtbr@Webfetti_52.com\bootstrap.js JS/Mindspark.C potentially unwanted application
C:\DATA\Documents and Settings\NetworkService\Local Settings\Application Data\NCH_EN\tbNCH_.dll a variant of Win32/Toolbar.Conduit.P potentially unwanted application
C:\DATA\Documents and Settings\NetworkService\Local Settings\Application Data\ToggleEN\tbTog0.dll a variant of Win32/Toolbar.Conduit.P potentially unwanted application
C:\DATA\Documents and Settings\Roger\Application Data\FBDownloader\DotNetCheck.exe a variant of Win32/Adware.Snoozer.J application
C:\DATA\Documents and Settings\Roger\Application Data\FBDownloader\fbDownloader.exe a variant of Win32/Adware.Snoozer.J application
C:\DATA\Documents and Settings\Roger\Application Data\FBDownloader\revert.dll a variant of Win32/Adware.Snoozer.N application
C:\DATA\Documents and Settings\Roger\Application Data\Sun\Java\Deployment\cache\6.0\54\2db86d36-1d1e4a21 a variant of Java/Mugademel.A trojan
C:\DATA\Documents and Settings\Roger\Application Data\systweak\ssd\SSDPTstub.exe Win32/Systweak.G potentially unwanted application
C:\DATA\Documents and Settings\Roger\Local Settings\Application Data\Microsoft\Windows Live Mail\Hotmail\Junk e-mail\04BD7DFC-0000009F.eml HTML/Pharmacy.A trojan
C:\DATA\Program Files\NCH Software\PhotoStage\photostage.exe a variant of Win32/Toolbar.Conduit.H potentially unwanted application
C:\DATA\Program Files\NCH Software\PhotoStage\pstagesetup_v2.10.exe a variant of Win32/Toolbar.Conduit.H potentially unwanted application
C:\DATA\Program Files\NCH Software\PhotoStage\uninst.exe a variant of Win32/Toolbar.Conduit.H potentially unwanted application
C:\DATA\Program Files\NCH Software\Prism\prism.exe a variant of Win32/Toolbar.Conduit.K potentially unwanted application
C:\DATA\Program Files\NCH Software\Prism\prismsetup_v1.61.exe a variant of Win32/Toolbar.Conduit.K potentially unwanted application
C:\DATA\Program Files\NCH Software\Prism\uninst.exe a variant of Win32/Toolbar.Conduit.K potentially unwanted application
C:\DATA\Program Files\NCH Software\VideoPad\uninst.exe a variant of Win32/Toolbar.Conduit.H potentially unwanted application
C:\DATA\Program Files\NCH Software\VideoPad\videopad.exe a variant of Win32/Toolbar.Conduit.H potentially unwanted application
C:\DATA\Program Files\NCH Software\VideoPad\vpsetup(1)_v2.40.exe a variant of Win32/Toolbar.Conduit.H potentially unwanted application
C:\DATA\Program Files\NCH Software\VideoPad\vpsetup_v2.30.exe a variant of Win32/Toolbar.Conduit.H potentially unwanted application
C:\DATA\Program Files\NCH Swift Sound\ExpressBurn\burnsetup_v4.40.exe a variant of Win32/Toolbar.Conduit.J potentially unwanted application
C:\DATA\Program Files\NCH Swift Sound\ExpressBurn\expressburn.exe a variant of Win32/Toolbar.Conduit.J potentially unwanted application
C:\DATA\Program Files\NCH Swift Sound\ExpressBurn\uninst.exe a variant of Win32/Toolbar.Conduit.J potentially unwanted application
C:\DATA\Program Files\NCH Swift Sound\MixPad\mixpad.exe a variant of Win32/Toolbar.Conduit.H potentially unwanted application
C:\DATA\Program Files\NCH Swift Sound\MixPad\mpsetup_v2.45.exe a variant of Win32/Toolbar.Conduit.H potentially unwanted application
C:\DATA\Program Files\NCH Swift Sound\MixPad\uninst.exe a variant of Win32/Toolbar.Conduit.H potentially unwanted application
C:\DATA\Program Files\NCH Swift Sound\Switch\switch.exe a variant of Win32/Toolbar.Conduit.H potentially unwanted application
C:\DATA\Program Files\NCH Swift Sound\Switch\switchsetup_v4.14.exe a variant of Win32/Toolbar.Conduit.H potentially unwanted application
C:\DATA\Program Files\NCH Swift Sound\Switch\uninst.exe a variant of Win32/Toolbar.Conduit.H potentially unwanted application
C:\DATA\Program Files\NCH Swift Sound\WavePad\uninst.exe a variant of Win32/Toolbar.Conduit.H potentially unwanted application
C:\DATA\Program Files\NCH Swift Sound\WavePad\wavepad.exe a variant of Win32/Toolbar.Conduit.H potentially unwanted application
C:\DATA\Program Files\NCH Swift Sound\WavePad\wpsetup_v4.58.exe a variant of Win32/Toolbar.Conduit.H potentially unwanted application
C:\DATA\Program Files\Smart Driver Updater\SDULauncher.exe a variant of Win32/Adware.SpeedingUpMyPC.AN application
C:\DATA\Program Files\Smart Driver Updater\SDUSchedule.exe a variant of Win32/Adware.SpeedingUpMyPC.AL application
C:\DATA\Program Files\Smart Driver Updater\SDUSmartScan.exe a variant of Win32/Adware.SpeedingUpMyPC.C application
C:\DATA\Program Files\Smart Driver Updater\SDUUninstaller.exe a variant of Win32/Adware.SpeedingUpMyPC.AL application
C:\DATA\Program Files\Smart Driver Updater\SmartDriverUpdater.exe a variant of Win32/Adware.SpeedingUpMyPC.AM application
C:\DATA\Program Files\Webfetti_52\bar\1.bin\52auxstb.dll a variant of Win32/Toolbar.MyWebSearch.W potentially unwanted application
C:\DATA\Program Files\Webfetti_52\bar\1.bin\52barsvc.exe a variant of Win32/Toolbar.MyWebSearch.AN potentially unwanted application
C:\DATA\Program Files\Webfetti_52\bar\1.bin\52brmon.exe a variant of Win32/Toolbar.MyWebSearch.AE potentially unwanted application
C:\DATA\Program Files\Webfetti_52\bar\1.bin\52brstub.dll a variant of Win32/Toolbar.MyWebSearch.AC potentially unwanted application
C:\DATA\Program Files\Webfetti_52\bar\1.bin\52datact.dll a variant of Win32/Toolbar.MyWebSearch.AA potentially unwanted application
C:\DATA\Program Files\Webfetti_52\bar\1.bin\52dlghk.dll a variant of Win32/Toolbar.MyWebSearch.AA potentially unwanted application
C:\DATA\Program Files\Webfetti_52\bar\1.bin\52dyn.dll a variant of Win32/Toolbar.MyWebSearch.AC potentially unwanted application
C:\DATA\Program Files\Webfetti_52\bar\1.bin\52feedmg.dll a variant of Win32/Toolbar.MyWebSearch.AA potentially unwanted application
C:\DATA\Program Files\Webfetti_52\bar\1.bin\52highin.exe a variant of Win32/Toolbar.MyWebSearch.AN potentially unwanted application
C:\DATA\Program Files\Webfetti_52\bar\1.bin\52hkstub.dll a variant of Win32/Toolbar.MyWebSearch.AM potentially unwanted application
C:\DATA\Program Files\Webfetti_52\bar\1.bin\52htmlmu.dll a variant of Win32/Toolbar.MyWebSearch.AA potentially unwanted application
C:\DATA\Program Files\Webfetti_52\bar\1.bin\52httpct.dll a variant of Win32/Toolbar.MyWebSearch.AA potentially unwanted application
C:\DATA\Program Files\Webfetti_52\bar\1.bin\52ieovr.dll a variant of Win32/Toolbar.MyWebSearch.P potentially unwanted application
C:\DATA\Program Files\Webfetti_52\bar\1.bin\52impipe.exe a variant of Win32/Toolbar.MyWebSearch.W potentially unwanted application
C:\DATA\Program Files\Webfetti_52\bar\1.bin\52medint.exe a variant of Win32/Toolbar.MyWebSearch.AN potentially unwanted application
C:\DATA\Program Files\Webfetti_52\bar\1.bin\52mlbtn.dll a variant of Win32/Toolbar.MyWebSearch.AC potentially unwanted application
C:\DATA\Program Files\Webfetti_52\bar\1.bin\52msg.dll a variant of Win32/Toolbar.MyWebSearch.AA potentially unwanted application
C:\DATA\Program Files\Webfetti_52\bar\1.bin\52Plugin.dll a variant of Win32/Toolbar.MyWebSearch potentially unwanted application
C:\DATA\Program Files\Webfetti_52\bar\1.bin\52radio.dll a variant of Win32/Toolbar.MyWebSearch.AC potentially unwanted application
C:\DATA\Program Files\Webfetti_52\bar\1.bin\52regfft.dll a variant of Win32/Toolbar.MyWebSearch.AA potentially unwanted application
C:\DATA\Program Files\Webfetti_52\bar\1.bin\52reghk.dll a variant of Win32/Toolbar.MyWebSearch.W potentially unwanted application
C:\DATA\Program Files\Webfetti_52\bar\1.bin\52regiet.dll a variant of Win32/Toolbar.MyWebSearch.AA potentially unwanted application
C:\DATA\Program Files\Webfetti_52\bar\1.bin\52script.dll a variant of Win32/Toolbar.MyWebSearch.AA potentially unwanted application
C:\DATA\Program Files\Webfetti_52\bar\1.bin\52skin.dll a variant of Win32/Toolbar.MyWebSearch.AA potentially unwanted application
C:\DATA\Program Files\Webfetti_52\bar\1.bin\52sknlcr.dll a variant of Win32/Toolbar.MyWebSearch.AC potentially unwanted application
C:\DATA\Program Files\Webfetti_52\bar\1.bin\52tpinst.dll a variant of Win32/Toolbar.MyWebSearch.AA potentially unwanted application
C:\DATA\Program Files\Webfetti_52\bar\1.bin\52uabtn.dll a variant of Win32/Toolbar.MyWebSearch.AA potentially unwanted application
C:\DATA\Program Files\Webfetti_52\bar\1.bin\BOOTSTRAP.JS JS/Mindspark.C potentially unwanted application
C:\DATA\Program Files\Webfetti_52\bar\1.bin\CREXT.DLL a variant of Win32/Toolbar.MyWebSearch.W potentially unwanted application
C:\DATA\Program Files\Webfetti_52\bar\1.bin\CrExtP52.exe a variant of Win32/Toolbar.MyWebSearch.W potentially unwanted application
C:\DATA\Program Files\Webfetti_52\bar\1.bin\NP52Stub.dll a variant of Win32/Toolbar.MyWebSearch.AH potentially unwanted application
C:\DATA\Program Files\Webfetti_52\bar\1.bin\T8EXTEX.DLL a variant of Win32/Toolbar.MyWebSearch.AU potentially unwanted application
C:\DATA\Program Files\Webfetti_52\bar\1.bin\T8EXTPEX.DLL a variant of Win32/Toolbar.MyWebSearch.AC potentially unwanted application
C:\DATA\Program Files\Webfetti_52\bar\1.bin\T8HTML.DLL a variant of Win32/Toolbar.MyWebSearch.F potentially unwanted application
C:\DATA\Program Files\Webfetti_52\bar\1.bin\T8TICKER.DLL a variant of Win32/Toolbar.MyWebSearch.AC potentially unwanted application
C:\DATA\Program Files\Win-Test\wt.exe a variant of Win32/Packed.Themida suspicious application
C:\DATA\RECYCLER\S-1-5-21-796845957-1788223648-725345543-1003\Dc126\Quarantine\C\Program Files\WeatherBlink\bar\1.bin\CREXT.DLL.vir a variant of Win32/Toolbar.MyWebSearch.W potentially unwanted application
C:\DATA\RECYCLER\S-1-5-21-796845957-1788223648-725345543-1003\Dc126\Quarantine\C\Program Files\WeatherBlink\bar\1.bin\CrExtPgc.exe.vir a variant of Win32/Toolbar.MyWebSearch.W potentially unwanted application
C:\DATA\RECYCLER\S-1-5-21-796845957-1788223648-725345543-1003\Dc126\Quarantine\C\Program Files\WeatherBlink\bar\1.bin\gcauxstb.dll.vir Win32/Toolbar.MyWebSearch.W potentially unwanted application
C:\DATA\RECYCLER\S-1-5-21-796845957-1788223648-725345543-1003\Dc126\Quarantine\C\Program Files\WeatherBlink\bar\1.bin\gcdatact.dll.vir a variant of Win32/Toolbar.MyWebSearch.AA potentially unwanted application
C:\DATA\RECYCLER\S-1-5-21-796845957-1788223648-725345543-1003\Dc126\Quarantine\C\Program Files\WeatherBlink\bar\1.bin\gcdlghk.dll.vir Win32/Toolbar.MyWebSearch.AA potentially unwanted application
C:\DATA\RECYCLER\S-1-5-21-796845957-1788223648-725345543-1003\Dc126\Quarantine\C\Program Files\WeatherBlink\bar\1.bin\gcdyn.dll.vir Win32/Toolbar.MyWebSearch.AA potentially unwanted application
C:\DATA\RECYCLER\S-1-5-21-796845957-1788223648-725345543-1003\Dc126\Quarantine\C\Program Files\WeatherBlink\bar\1.bin\gcfeedmg.dll.vir Win32/Toolbar.MyWebSearch.AA potentially unwanted application
C:\DATA\RECYCLER\S-1-5-21-796845957-1788223648-725345543-1003\Dc126\Quarantine\C\Program Files\WeatherBlink\bar\1.bin\gchighin.exe.vir Win32/Toolbar.MyWebSearch.AA potentially unwanted application
C:\DATA\RECYCLER\S-1-5-21-796845957-1788223648-725345543-1003\Dc126\Quarantine\C\Program Files\WeatherBlink\bar\1.bin\gchkstub.dll.vir Win32/Toolbar.MyWebSearch.AA potentially unwanted application
C:\DATA\RECYCLER\S-1-5-21-796845957-1788223648-725345543-1003\Dc126\Quarantine\C\Program Files\WeatherBlink\bar\1.bin\gchtmlmu.dll.vir a variant of Win32/Toolbar.MyWebSearch.AA potentially unwanted application
C:\DATA\RECYCLER\S-1-5-21-796845957-1788223648-725345543-1003\Dc126\Quarantine\C\Program Files\WeatherBlink\bar\1.bin\gchttpct.dll.vir Win32/Toolbar.MyWebSearch.AA potentially unwanted application
C:\DATA\RECYCLER\S-1-5-21-796845957-1788223648-725345543-1003\Dc126\Quarantine\C\Program Files\WeatherBlink\bar\1.bin\gcidle.dll.vir Win32/Toolbar.MyWebSearch.AA potentially unwanted application
C:\DATA\RECYCLER\S-1-5-21-796845957-1788223648-725345543-1003\Dc126\Quarantine\C\Program Files\WeatherBlink\bar\1.bin\gcieovr.dll.vir a variant of Win32/Toolbar.MyWebSearch.P potentially unwanted application
C:\DATA\RECYCLER\S-1-5-21-796845957-1788223648-725345543-1003\Dc126\Quarantine\C\Program Files\WeatherBlink\bar\1.bin\gcimpipe.exe.vir Win32/Toolbar.MyWebSearch.W potentially unwanted application
C:\DATA\RECYCLER\S-1-5-21-796845957-1788223648-725345543-1003\Dc126\Quarantine\C\Program Files\WeatherBlink\bar\1.bin\gcmedint.exe.vir Win32/Toolbar.MyWebSearch.AA potentially unwanted application
C:\DATA\RECYCLER\S-1-5-21-796845957-1788223648-725345543-1003\Dc126\Quarantine\C\Program Files\WeatherBlink\bar\1.bin\gcmlbtn.dll.vir Win32/Toolbar.MyWebSearch.AA potentially unwanted application
C:\DATA\RECYCLER\S-1-5-21-796845957-1788223648-725345543-1003\Dc126\Quarantine\C\Program Files\WeatherBlink\bar\1.bin\gcmsg.dll.vir Win32/Toolbar.MyWebSearch.AA potentially unwanted application
C:\DATA\RECYCLER\S-1-5-21-796845957-1788223648-725345543-1003\Dc126\Quarantine\C\Program Files\WeatherBlink\bar\1.bin\gcPlugin.dll.vir a variant of Win32/Toolbar.MyWebSearch potentially unwanted application
C:\DATA\RECYCLER\S-1-5-21-796845957-1788223648-725345543-1003\Dc126\Quarantine\C\Program Files\WeatherBlink\bar\1.bin\gcradio.dll.vir Win32/Toolbar.MyWebSearch.AA potentially unwanted application
C:\DATA\RECYCLER\S-1-5-21-796845957-1788223648-725345543-1003\Dc126\Quarantine\C\Program Files\WeatherBlink\bar\1.bin\gcregfft.dll.vir Win32/Toolbar.MyWebSearch.AA potentially unwanted application
C:\DATA\RECYCLER\S-1-5-21-796845957-1788223648-725345543-1003\Dc126\Quarantine\C\Program Files\WeatherBlink\bar\1.bin\gcreghk.dll.vir a variant of Win32/Toolbar.MyWebSearch.W potentially unwanted application
C:\DATA\RECYCLER\S-1-5-21-796845957-1788223648-725345543-1003\Dc126\Quarantine\C\Program Files\WeatherBlink\bar\1.bin\gcregiet.dll.vir Win32/Toolbar.MyWebSearch.AA potentially unwanted application
C:\DATA\RECYCLER\S-1-5-21-796845957-1788223648-725345543-1003\Dc126\Quarantine\C\Program Files\WeatherBlink\bar\1.bin\gcscript.dll.vir Win32/Toolbar.MyWebSearch.AA potentially unwanted application
C:\DATA\RECYCLER\S-1-5-21-796845957-1788223648-725345543-1003\Dc126\Quarantine\C\Program Files\WeatherBlink\bar\1.bin\gcskin.dll.vir a variant of Win32/Toolbar.MyWebSearch.AA potentially unwanted application
C:\DATA\RECYCLER\S-1-5-21-796845957-1788223648-725345543-1003\Dc126\Quarantine\C\Program Files\WeatherBlink\bar\1.bin\gcsknlcr.dll.vir Win32/Toolbar.MyWebSearch.AA potentially unwanted application
C:\DATA\RECYCLER\S-1-5-21-796845957-1788223648-725345543-1003\Dc126\Quarantine\C\Program Files\WeatherBlink\bar\1.bin\gcskplay.exe.vir Win32/Toolbar.MyWebSearch.W potentially unwanted application
C:\DATA\RECYCLER\S-1-5-21-796845957-1788223648-725345543-1003\Dc126\Quarantine\C\Program Files\WeatherBlink\bar\1.bin\gctpinst.dll.vir Win32/Toolbar.MyWebSearch.AA potentially unwanted application
C:\DATA\RECYCLER\S-1-5-21-796845957-1788223648-725345543-1003\Dc126\Quarantine\C\Program Files\WeatherBlink\bar\1.bin\gcuabtn.dll.vir Win32/Toolbar.MyWebSearch.AA potentially unwanted application
C:\DATA\RECYCLER\S-1-5-21-796845957-1788223648-725345543-1003\Dc126\Quarantine\C\Program Files\WeatherBlink\bar\1.bin\NPgcStub.dll.vir Win32/Toolbar.MyWebSearch.T potentially unwanted application
C:\DATA\RECYCLER\S-1-5-21-796845957-1788223648-725345543-1003\Dc126\Quarantine\C\Program Files\WeatherBlink\bar\1.bin\T8EXTEX.DLL.vir Win32/Toolbar.MyWebSearch.AA potentially unwanted application
C:\DATA\RECYCLER\S-1-5-21-796845957-1788223648-725345543-1003\Dc126\Quarantine\C\Program Files\WeatherBlink\bar\1.bin\T8EXTPEX.DLL.vir Win32/Toolbar.MyWebSearch.AA potentially unwanted application
C:\DATA\RECYCLER\S-1-5-21-796845957-1788223648-725345543-1003\Dc126\Quarantine\C\Program Files\WeatherBlink\bar\1.bin\T8HTML.DLL.vir a variant of Win32/Toolbar.MyWebSearch.F potentially unwanted application
C:\DATA\RECYCLER\S-1-5-21-796845957-1788223648-725345543-1003\Dc126\Quarantine\C\Program Files\WeatherBlink\bar\1.bin\T8TICKER.DLL.vir a variant of Win32/Toolbar.MyWebSearch.AC potentially unwanted application
C:\DATA\WINDOWS\system32\config\systemprofile\AppData\LocalLow\SweetNT.crx a variant of Win32/SweetIM.L potentially unwanted application
C:\Program Files\WinZip\Utils\WzSysScan\WINZIPSS.exe a variant of Win32/Systweak.L potentially unwanted application
C:\Program Files\WinZip\Utils\WzSysScan\WINZIPSSHelper.dll a variant of Win32/Systweak.N potentially unwanted application
C:\Program Files\WinZip\Utils\WzSysScan\WINZIPSSPrivacyProtector.exe a variant of Win32/Systweak.L potentially unwanted application
C:\Program Files\WinZip\Utils\WzSysScan\WINZIPSSRegClean.exe a variant of Win32/Systweak.L potentially unwanted application
C:\Program Files\WinZip\Utils\WzSysScan\WINZIPSSRegistryOptimizer.exe a variant of Win32/Systweak.L potentially unwanted application
C:\Program Files\WinZip\Utils\WzSysScan\WINZIPSSSystemCleaner.exe a variant of Win32/Systweak.L potentially unwanted application
C:\Users\Tom Read\AppData\Roaming\Setup5769.exe a variant of Win32/DealPly.CA potentially unwanted application
C:\Users\Tom Read\Desktop\Old Desktop\Admin\iTunes32-bit.exe a variant of Win32/OpenInstall potentially unwanted application
C:\Users\Tom Read\Desktop\Old Desktop\Admin\rminstall.exe Win32/RegistryMechanic.B potentially unwanted application
C:\Users\Tom Read\Desktop\Old Desktop\Admin\switchsetup.exe a variant of Win32/Toolbar.Conduit.H potentially unwanted application
C:\Users\Tom Read\Desktop\Old Desktop\Admin\vpsetup(1).exe a variant of Win32/Toolbar.Conduit.H potentially unwanted application
C:\Users\Tom Read\Desktop\Old Desktop\Admin\vpsetup.exe a variant of Win32/Toolbar.Conduit.H potentially unwanted application
C:\Users\Tom Read\Desktop\Old Desktop\Old Firefox Data\015y0bgx.default\prefs-1.js JS/SecurityDisabler.A.Gen potentially unwanted application
C:\Users\Tom Read\Desktop\Old Desktop\Old Firefox Data\015y0bgx.default\prefs.js JS/SecurityDisabler.A.Gen potentially unwanted application
C:\Users\Tom Read\Desktop\Old Desktop\Old Firefox Data\015y0bgx.default\user.js JS/SecurityDisabler.A.Gen potentially unwanted application
C:\Users\Tom Read\Documents\Downloads\wt-4.8.0-demo.exe a variant of Win32/Packed.Themida suspicious application
C:\Users\Tom Read\Downloads\ccsetup532.exe Win32/Bundled.Toolbar.Google.D potentially unsafe application
C:\Users\Tom Read\Downloads\winzip18-lan_en.exe a variant of Win32/InstallCore.AEO.gen potentially unwanted application
C:\Windows\Installer\1ad976.msi a variant of Win32/Systweak.L potentially unwanted application,a variant of Win32/Systweak.N potentially unwanted application
 
Eek.  Now about to "Clean All".


#9 m1eyp

m1eyp
  • Topic Starter

  • Members
  • 66 posts
  • OFFLINE
  •  
  • Local time:03:07 PM

Posted 31 July 2017 - 02:38 PM

Security Check by glax24 log:

 

SecurityCheck by glax24 & Severnyj v.1.4.0.52 [25.07.17]
WebSite: www.safezone.cc
DateLog: 31.07.2017 20:35:56
Path starting: C:\Users\Tom Read\AppData\Local\Temp\SecurityCheck\SecurityCheck.exe
Log directory: C:\SecurityCheck\
IsAdmin: True
User: Tom Read
VersionXML: 4.53is-28.07.2017
___________________________________________________________________________
 
Windows 7(6.1.7601) Service Pack 1 (x64) HomePremium Lang: English(0409)
Installation date OS: 30.07.2014 12:06:59
LicenseStatus: Windows® 7, HomePremium edition The machine is permanently activated.
Boot Mode: Normal
Default Browser: C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
SystemDrive: C: FS: [NTFS] Capacity: [1862.9 Gb] Used: [175.4 Gb] Free: [1687.5 Gb]
------------------------------- [ Windows ] -------------------------------
Internet Explorer 11.0.9600.18738
User Account Control enabled
Automatically download and schedule installation
Date install updates: 2017-07-13 17:57:34
Windows Update (wuauserv) - The service is running
Security Center (wscsvc) - The service is running
Remote Registry (RemoteRegistry) - The service has stopped
SSDP Discovery (SSDPSRV) - The service is running
Remote Desktop Services (TermService) - The service has stopped
Windows Remote Management (WS-Management) (WinRM) - The service has stopped
------------------------------ [ MS Office ] ------------------------------
Microsoft Office 2003 v.11.0.8173.0
---------------------------- [ Antivirus_WMI ] ----------------------------
Microsoft Security Essentials (enabled and up to date)
--------------------------- [ FirewallWindows ] ---------------------------
Windows Firewall (MpsSvc) - The service is running
--------------------------- [ AntiSpyware_WMI ] ---------------------------
Spybot - Search and Destroy (enabled and out of date)
Microsoft Security Essentials (enabled and up to date)
Windows Defender (disabled and up to date)
---------------------- [ AntiVirusFirewallInstall ] -----------------------
McAfee Security Scan Plus v.3.11.587.1
Microsoft Security Essentials v.4.10.209.0
-------------------------- [ SecurityUtilities ] --------------------------
Malwarebytes version 3.1.2.1733 v.3.1.2.1733
Spybot - Search & Destroy v.2.4.40
--------------------------- [ OtherUtilities ] ----------------------------
Microsoft Silverlight v.5.1.50907.0
--------------------------- [ AdobeProduction ] ---------------------------
Adobe Flash Player 26 ActiveX v.26.0.0.137
Adobe Flash Player 26 NPAPI v.26.0.0.137
Adobe Flash Player 26 PPAPI v.26.0.0.137
------------------------------- [ Browser ] -------------------------------
Google Chrome v.60.0.3112.78
Mozilla Firefox 54.0.1 (x86 en-US) v.54.0.1
--------------------------- [ RunningProcess ] ----------------------------
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe v.60.0.3112.78
------------------ [ AntivirusFirewallProcessServices ] -------------------
C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe v.3.0.0.1068
Malwarebytes Service (MBAMService) - The service is running
C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe v.3.1.0.479
C:\Program Files\McAfee Security Scan\3.11.587\SSScheduler.exe v.3.11.587.0
McAfee Security Scan Component Host Service (McComponentHostService) - The service has stopped
Spybot-S&D 2 Scanner Service (SDScannerService) - The service is running
C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe v.2.4.40.217
Spybot-S&D 2 Security Center Service (SDWSCService) - The service is running
C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe v.2.5.55.3
Spybot-S&D 2 Updating Service (SDUpdateService) - The service is running
C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe v.2.5.44.79
C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe v.2.4.40.129
Microsoft Antimalware Service (MsMpSvc) - The service is running
C:\Program Files\Microsoft Security Client\MsMpEng.exe v.4.10.209.0
C:\Program Files\Microsoft Security Client\msseces.exe v.4.10.209.0
Microsoft Network Inspection (NisSrv) - The service is running
C:\Program Files\Microsoft Security Client\NisSrv.exe v.4.10.209.0
Windows Defender (WinDefend) - The service has stopped
----------------------------- [ End of Log ] ------------------------------


#10 m1eyp

m1eyp
  • Topic Starter

  • Members
  • 66 posts
  • OFFLINE
  •  
  • Local time:03:07 PM

Posted 31 July 2017 - 02:47 PM

Well buddy215, your advice thus far has been monumental.  I don't remember my computer running as well as this for many years.  No doubt there's more advice to come - maybe about ongoing security configurations etc, but for everything so far - a huge thank you!



#11 buddy215

buddy215

  • Moderator
  • 13,411 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:West Tennessee
  • Local time:09:07 AM

Posted 31 July 2017 - 03:12 PM

A lot of crapola removed...good that has had positive effect.

 

Suggest uninstalling Spybot and McAfee programs. They should be listed in your list of installed programs.

 

Other than that...if you are not getting any error notices...not unusual after removing so much crapola...then I think you

are good to go.

You're welcome....happy surfin'


“Every atom in your body came from a star that exploded and the atoms in your left hand probably came from a different star than your right hand. It really is the most poetic thing I know about physics...you are all stardust.”Lawrence M. Krauss
A 1792 U.S. penny, designed in part by Thomas Jefferson and George Washington, reads “Liberty Parent of Science & Industry.”

#12 m1eyp

m1eyp
  • Topic Starter

  • Members
  • 66 posts
  • OFFLINE
  •  
  • Local time:03:07 PM

Posted 11 August 2017 - 03:21 PM

Hello again,

 

Unfortunately, we seem to be back at square one.  My PC started slowing down again a couple of days after our last exchange in this topic, and now it hangs sometimes for 3-5 minutes at a time, with multiple large instances of Chrome needing to be terminated via Task Manager.

 

The Malwarebytes trial (which has a day to go) keeps blocking some website called "online-metrix" everytime I go to an online banking log-in page, which is extremely worrying.  

 

I've run the CCCleaner and Malwarebytes scans again several times, but no threats are found.

 

Your advice would be appreciated.



#13 buddy215

buddy215

  • Moderator
  • 13,411 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:West Tennessee
  • Local time:09:07 AM

Posted 12 August 2017 - 07:11 AM

Not sure if you have acquired some new malware or something was missed in earlier scans. Best to resolve by starting a new

topic in the malware removal forum by following the directions below. You may want to run another scan using Eset Online scanner before

starting the new post....but don't do it after creating the FRST logs.

 

Please follow the instructions in the Malware Removal and Log Section Preparation Guide starting at Step 6.

  • If you cannot complete a step, then skip it and continue with the next.
  • In Step 6 there are instructions for downloading and running FRST which will create two logs.

When you have done that, post your logs in the Virus, Trojan, Spyware, and Malware Removal Logs forum, NOT here, for assistance by the Malware Response Team.

Start a new topic, give it a relevant title and post your log(s) along with a brief description of your problem, a summary of any anti-malware tools you have used and a summary of any steps that you have performed on your own. If you cannot produce any of the required logs...start the new topic anyway. Explain that you followed the Prep. Guide, were unable to create the logs, and describe what happened when you tried to create them. A member of the Malware Removal Team will walk you through, step by step, on how to clean your computer.

After doing this, please reply back in this thread with a link to the new topic so we can close this one.

 

DO NOT bump your new topic. Wait for a response from one of the Team Members.


“Every atom in your body came from a star that exploded and the atoms in your left hand probably came from a different star than your right hand. It really is the most poetic thing I know about physics...you are all stardust.”Lawrence M. Krauss
A 1792 U.S. penny, designed in part by Thomas Jefferson and George Washington, reads “Liberty Parent of Science & Industry.”

#14 m1eyp

m1eyp
  • Topic Starter

  • Members
  • 66 posts
  • OFFLINE
  •  
  • Local time:03:07 PM

Posted 18 August 2017 - 03:41 AM

After following all the excellent advice in this earlier thread:

 

https://www.bleepingcomputer.com/forums/t/652860/multiple-instances-of-chrome-slowing-down-my-pc/#entry4308378

Mod Edit:  No logs, merged with AII topic linked above - Hamluis.

 

...my PC operated really well, back to lightning speed for a couple of days.  Then very quickly, it got really sluggish again, and I could only relieve (temporarily) the situation by launching the Task Manager and killing off the multiple instances of Google Chrome, some of which were pretty large in size.

 

I am now, in accordance with advice in the last post of that thread, starting a new support thread, and first just running ESET Scanner again.  I will post any results below:


Edited by hamluis, 18 August 2017 - 05:05 AM.


#15 m1eyp

m1eyp
  • Topic Starter

  • Members
  • 66 posts
  • OFFLINE
  •  
  • Local time:03:07 PM

Posted 18 August 2017 - 06:57 AM

Link to the new topic:

 

https://www.bleepingcomputer.com/forums/t/654645/pc-slow-often-hanging-and-multiple-large-instances-of-chrome/






0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users