This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Computer misbehaving and time out just isn't working

10 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello,

 

I find I need some help with a wonky acting computer.  I'm using Windows 10, the PC is practically brand new.  My anti-virus and anti-malware programs are Malware Bytes Premium and System Mechanic Pro.  I generally use Google Chrome as my browser, but I have used Firefox and Edge.  I use Mozilla Thunderbird as my email client.   Just in the last few days, Thunderbird and favorite Website YouTube have been misbehaving.  Thunderbird has been stalling and freezing and YouTube won't let me reply to posts, because when I attempt to, the whole post area disappears.  I tried different browsers to determine if the problem was browser specific, but it's not.  I tried the fixes suggested for Thunderbird, to see if that helped, but it didn't.   I have done full scans of my PC to check for viruses., but they report back that everything is ok.   I don't know why all of a sudden I am having problems.  Could it be that there is a virus of some sort my programs aren't detecting?  My virus programs are up to date. 

 

Any help or suggestions anyone could give me would be great.  Here is the latest report as of today from my Malware Bytes Premium.

 

 

Welcome

[external image: xlK5Hdb.png]Farbar Recovery Scan Tool (FRST) Scan
  • Please download Farbar Recovery Scan Tool (x32) or Farbar Recovery Scan Tool (x64) and save the file to your Desktop.
  • Note: Download and run the version compatible with your system (32 or 64-bit). Download both if you're unsure; only one will run.
  • Right-Click FRST.exe / FRST64.exe and select [external image: AVOiBNU.jpg]Run as administrator to run the programme.
  • Click Yes to the disclaimer.
  • Ensure the Addition.txt box is checked.
  • Click the Scan button and let the programme run.
  • Upon completion, click OK, then OK on the Addition.txt pop up screen.
  • Two logs (FRST.txt & Addition.txt) will now be open on your Desktop. Copy the contents of both logs and paste in your next reply.
Hello Juliet,
I am typing this on a notepad and then pasting it in the message field to reply to your post. 
It seems now I can't edit any post I make,, now matter what website I am on.
The two logs are below.  Thank you so much for your help.

By chance, are you running 2 antivirus?
System Mechanic Pro and CYREN Antivirus/Commtouch\AntiVirus5

Need to have only 1

You have a program named iolo technologies' System Mechanic on your computer that are supposedly registry Optimizers/cleaners. A registry cleaner will not increase your system's speed or performance, and has the potential to break your registry to the point that your PC is no longer bootable.
Why you should not use Registry Cleaners and Optimization Tools
https://www.bleepingcomputer.com/forums/t/407147/answers-to-common-security-questions-best-practices/?p=2853053

~~~~~~~~~~~~~~~~~~~~``

****
Start Farbar Recovery Scan Tool with Administrator privileges
(Right click on the FRST icon and select Run as administrator)

highlight on the text below and select Copy.
beginning with Start:: and finishing with End::


Start::
CloseProcesses:
CreateRestorePoint:
CustomCLSID: HKU\S-1-5-21-2748143367-3355847530-1694364109-1001_Classes\CLSID\{84B5A313-CD5D-4904-8BA2-AFDC81C1B309}\InprocServer32 -> C:\Users\Earl\AppData\Local\GoToMeeting\7716\G2MOutlookAddin64.dll => No File
Task: {1EAD3179-1A03-4551-8CBA-EA3E072C70D2} - System32\Tasks\App Explorer => C:\Users\Earl\AppData\Local\Host App Service\Engine\HostAppServiceUpdater.exe [2017-12-18] (SweetLabs, Inc) <==== ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Restriction <==== ATTENTION
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <==== ATTENTION
SearchScopes: HKU\S-1-5-21-2748143367-3355847530-1694364109-1001 -> DefaultScope {F332FEA7-39F0-4FED-ABC1-C862BEA970C1} URL =
SearchScopes: HKU\S-1-5-21-2748143367-3355847530-1694364109-1001 -> {F332FEA7-39F0-4FED-ABC1-C862BEA970C1} URL =
BHO: Webroot Vault -> {c8d5d964-2be8-4c5b-8cf5-6e975aa88504} -> C:\ProgramData\WRData\pkg\LPBar64.dll => No File
BHO-x32: Webroot Vault -> {c8d5d964-2be8-4c5b-8cf5-6e975aa88504} -> C:\ProgramData\WRData\pkg\LPBar.dll => No File
Toolbar: HKLM - Webroot Toolbar - {97ab88ef-346b-4179-a0b1-7445896547a5} - C:\ProgramData\WRData\pkg\LPBar64.dll No File
Toolbar: HKLM-x32 - Webroot Toolbar - {97ab88ef-346b-4179-a0b1-7445896547a5} - C:\ProgramData\WRData\pkg\LPBar.dll No File
Emptytemp:
End::


Press the Fix button.
If for some reason the tool needs a restart, please make sure you let the system restart normally. After that let the tool complete its run.
When finished FRST will generate a log on the Desktop (Fixlog.txt). Please post it to your reply.



******

[external image: zcMPezJ.png]AdwCleaner

  • Download AdwCleaner and move it to your Desktop
  • Right-click on AdwCleaner.exe and select [external image: Spcusrh.png]Run as Administrator (for Windows Vista, 7, 8, 8.1 and 10 users)
  • Accept the EULA (I accept), then click on Scan
  • Let the scan complete. Once it's done, make sure that every item listed in the different tabs is checked and click on the Clean button. This will kill all active processes
    🖼Click to load external image (V7SD4El.png)
  • Once the cleaning process is complete, AdwCleaner will ask to restart your computer, do it
  • After the restart, a log will open when logging in. Please copy/paste the content of that log in your next reply

~~

[external image: RQKuhw1.png]RogueKiller

  • Download the right version of RogueKiller for your Windows version (32 or 64-bit)
  • Once done, move the executable file to your Desktop, right-click on it and select [external image: Spcusrh.png]Run as Administrator (for Windows Vista, 7, 8, 8.1 and 10 users)
  • Click on the Start Scan button in the right panel, which will bring you to another tab, and click on it again (this time it'll be in the bottom right corner)
  • Wait for the scan to complete
  • On completion, the results will be displayed
  • Check every single entry (threat found), and click on the Remove Selected button
  • On completion, the results will be displayed. Click on the Open Report button in the bottom left corner, followed by the Open TXT button (also in the bottom left corner)
  • This will open the report in Notepad. Copy/paste its content in your next reply,
  • created by Aura

~~

Please post
Fixlog.txt
AdwCleaner log
RogueKiller log

Hi Juliet,
 
I have completed the programs and have included the logs you asked for.  
I hope I got everything right.  I am actually typing this post, in the reply box,
​so something is right.   Here are the logs.

I am actually typing this post, in the reply box,
​so something is right.

Good deal

By chance, are you running 2 antivirus?
System Mechanic Pro and CYREN Antivirus/Commtouch\AntiVirus5


Let's update and run a scan with MalwareBytes

launch it and let it update his database. You might have to click on the little arrow by Scan Status in the middle right pane for it to do so

  • Once the database update is complete, click on the Scan tab, then select the Threat Scan button and click on Start Scan
  • Let the scan run, the time required to complete the scan depends of your system and computer specs
  • Once the scan is complete, make sure that the first checkbox at the top is checked (which will automatically check every detected item), then click on the Quarantine Selected button
    • Once the scan is complete, click on the Saves Results button, and select Copy to clipboard
      [external image: FhOtwqv.png]
    • From there, paste the content of the clipboard in your next reply
    • If it asks you to restart your computer to complete the removal, do so
  • Paste the content in your next reply

~~~~~~~~~~~~

[external image: G0tu5D9.png]Emsisoft Emergency Kit - Fix Mode
Follow the instructions below to run a scan using the Emsisoft Emergency Kit.

  • Download the Emsisoft Emergency Kit and execute it. From there, click on the Install button to extract the program in the EEK folder;
  • Once the extraction is complete, the EEK folder will open. Right-click on [external image: G0tu5D9.png]start emergency kit scanner.exe and select [external image: Spcusrh.png]Run as Administrator (for Windows Vista, 7, 8, 8.1 and 10 users);
  • EEK will suggest that you run an online update before using the program. Click on Yes to launch it.
  • After the update, click on Malware Scan under 2. Scan and accept to let EEK detect PUPs (click on Yes).
  • Once the scan is complete, make sure that every item in the list is checked, and click on the Quarantine selected button;
  • If it asks you for a reboot to delete some items, click on Ok to reboot automatically;
  • After the restart, open EEK again (in the C:\EEK folder);
  • This time, click on Logs;
  • From there, go under the Quarantine Log tab, and click on the Export button;
  • Save the log on your desktop, then open it, and copy/paste its content in your next reply;

created by Aura

 

Please post these logs when finished.

Hi Juliet,
 
I meant to get back to you yesterday, but I had something else to attend to.  The new log results are attached.
Now I have uninstalled System Mechanic temporarily, and I am only running Malware Bytes, but that free trial of 
Emsisoft found two issues apparently Malware Bytes missed, although they posed no risk.  Do you recommend
Malware Bytes over System Mechanic?

One thing to ensure your computer functions as it should is to have 1 security package installed and running.

CYREN internet security? is that still on the machine, offered as a free trial?, you downloaded as a secondary security?

MalwareBytes is anti-malware with other security features offered in the Premium version(paid for)great tool to have onboard and works well with other free version of antivirus.

Tell me what the computer is doing now.

Hi Juliet,

 

Do you mean by CYREN System Mechanic?  The two anti-virus or malware programs I had installed on my computer were/are System Mechanic and Malware Bytes.  I temporarily removed System Mechanic because you said some features of that program could make my computer un-rebootable, and that registry cleaners can actually slow down a computer. I had System Mechanic Professional installed on my computer.  So I still do have Malware Bytes on my computer.  I am thinking about getting that Emsisoft.  Could Malware Bytes be a good backup to Emsisoft?   Oh, my computer is running like new!!…  I am so pleased with the assistance you gave me, to get things running smoothly again.  My Thunderbird is working great now, and I now can reply to posts, without the reply area disappearing. 

 

Oh, umm should I remove the attachments that I inserted in my posts, for privacy sake?

Hi Juliet,
 
Do you mean by CYREN System Mechanic?  The two anti-virus or malware programs I had installed on my computer were/are System Mechanic and Malware Bytes.  I temporarily removed System Mechanic because you said some features of that program could make my computer un-rebootable, and that registry cleaners can actually slow down a computer. I had System Mechanic Professional installed on my computer.  So I still do have Malware Bytes on my computer.  I am thinking about getting that Emsisoft.  Could Malware Bytes be a good backup to Emsisoft?   Oh, my computer is running like new!!…  I am so pleased with the assistance you gave me, to get things running smoothly again.  My Thunderbird is working great now, and I now can reply to posts, without the reply area disappearing. 
 
Oh, umm should I remove the attachments that I inserted in my posts, for privacy sake?

Your logs to me showed CYREN System Mechanic as two different installed security apps. If it's 1 program thats all the better.

From what I know, MalwareBytes and Emsisoft work well together and should be a good set up for your computer.

Glad to hear the computer is running good again and as for attachments, yes you can delete those.

The below tool will remove tools I had you download with quarantine files.
DelFix
  • Please download DelFix or from Here and save the file to your Desktop.
  • Double-click DelFix.exe to run the programme.
  • Place a checkmark next to the following items:
  • Activate UAC
  • Remove disinfection tools
  • Click the Run button.
  • – This will remove the specialized tools we used to disinfect your system.
    Any leftover logs, files, folders or tools remaining on your Desktop which were not removed can be deleted manually (right-click the file + delete
    ).
***********************
  • Answers to common security questions - Best Practices by quietman7, MVP
  • How Malware Spreads - How did I get infected? by quietman7, MVP
  • Simple and easy ways to keep your computer safe and secure on the Internet by Lawrence Abrams, MVP
  • How to Prevent Malware by miekiemoes, MVP
  • How to backup and restore your data using Cobian Backup by YourHighness
  • Slow Computer/browser? It May Not Be Malware by quietman7, MVP
  • AdBlock is a browser add-on that blocks annoying banners, pop-ups and video ads.
  • [external image: E8I37RF.png]CryptoPrevent places policy restrictions on loading points for ransomware (eg. CryptoWall), helping prevent the execution of malware.
  • [external image: EG85Vjt.png]Malwarebytes Anti-Exploit (MBAE) is designed to prevent zero-day malware from exploiting vulnerable software.
  • [external image: 6YRrgUC.png]Malwarebytes Anti-Malware Premium (MBAM) works in real-time along side your Anti-Virus to prevent malware execution.
  • [external image: 3O8r9Uq.png] Sandboxie isolates programmes of your choice, preventing files from being written to your HDD unless approved by you.
  • [external image: DgW1XL2.png]Secunia PSI will scan your computer for vulnerable software that is outdated, and automatically find the latest update for you.
  • [external image: sHjS79L.png]Unchecky automatically removes checkmarks for bunlded software in programme installers; helping you avoid adware and PUPs.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI