This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

PC slow/unresponsive after time

18 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I typically let my PC run 24/7 with no issues. Lately, my PC has been hard locking when left alone. Hibernation is off, sleep is off. MalwareBytes/Windows Defender has not picked up anything out of the ordinary.

 

It began about a week ago and has been a daily issue. It started with a bluescreen followed by BOOTMGR missing. I was finally able to sign back in to Windows, but if PC is left alone (overnight/dinner), it is unresponsive after a few seconds of returning to it. When running fine, TaskManager doesn't showcase anything odd either. I am baffled.

 

I have downloaded some (maybe) sketchy games lately, but again, nothing was picked up by virus/malware software. This would possibly be my best guess as a cause.

 

Attached are my FRST logs.

Sorry for the delay,    I have a home schooler/virtual classroom here who uses my computer…….and it ain't pretty.
 
Not much of anything showing that  I would think is related to malware but we can check.

Start Farbar Recovery Scan Tool with Administrator privileges
(Right click on the FRST icon and select Run as administrator)

highlight on the text below and select Copy.
beginning with Start:: and finishing with End::
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Highlight the entire content of the quote box below and select Copy.

 

Start::
CloseProcesses:
CreateRestorePoint:
CHR HKLM\SOFTWARE\Policies\Google: Restriction <==== ATTENTION
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <==== ATTENTION
HKU\S-1-5-21-1325898818-1074576931-4225677256-1000\…\ChromeHTML: -> <==== ATTENTION
ContextMenuHandlers1: [MagicISO] -> {DB85C504-C730-49DD-BEC1-7B39C6103B7A} => -> No File
ContextMenuHandlers4: [MagicISO] -> {DB85C504-C730-49DD-BEC1-7B39C6103B7A} => -> No File
ContextMenuHandlers4: [PowerISO] -> {967B2D40-8B7D-4127-9049-61EA0C2C6DCE} => -> No File
ContextMenuHandlers5: [Gadgets] -> {6B9228DA-9C15-419e-856C-19E768A13BDC} => -> No File
ContextMenuHandlers6: [MagicISO] -> {DB85C504-C730-49DD-BEC1-7B39C6103B7A} => -> No File
ContextMenuHandlers6: [PowerISO] -> {967B2D40-8B7D-4127-9049-61EA0C2C6DCE} => -> No File
ShortcutWithArgument: C:\Users\Rappy\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\a3a1d6b8109861c5\Google Hangouts.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome_proxy.exe (Google LLC) -> –profile-directory=Default –app-id=nckgahadagoaajjgafhacjanaoiihapd
ShortcutWithArgument: C:\Users\Rappy\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\7cd27c6fdd0b5b45\Google Hangouts.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome_proxy.exe (Google LLC) -> –profile-directory="Profile 3" –app-id=nckgahadagoaajjgafhacjanaoiihapd
ShortcutWithArgument: C:\Users\Rappy\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\5d696d521de238c3\Timothy - Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC) -> –allow-file-access-from-files
ShortcutWithArgument: C:\Users\Rappy\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\225bb61db2f318c1\Timothy ([removed]) - Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC) -> –profile-directory="Profile 3"
AlternateDataStreams: C:\ProgramData\Temp:359B3BDA [368]
HKLM\…\.scr: SageThumbsImage.scr => "%1" /S <==== ATTENTION
SearchScopes: HKLM -> DefaultScope {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL =
Toolbar: HKU\S-1-5-21-1325898818-1074576931-4225677256-1000 -> No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File
Toolbar: HKU\S-1-5-21-1325898818-1074576931-4225677256-1000 -> No Name - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - No File
FirewallRules: [{74D9DF25-E547-49AA-A468-A748096BE228}] => (Allow) C:\Users\Rappy\AppData\Roaming\uTorrent\uTorrent.exe => No File
FirewallRules: [{351BC848-912D-4F10-8AF7-706907E6C84D}] => (Allow) C:\Users\Rappy\AppData\Roaming\uTorrent\uTorrent.exe => No File
FirewallRules: [{7F30673D-3791-4393-A776-96C7649F6AE2}] => (Allow) C:\Users\Rappy\AppData\Roaming\uTorrent\uTorrent.exe => No File
FirewallRules: [{62004DAC-148D-458A-937E-951366A8788F}] => (Allow) C:\Users\Rappy\AppData\Roaming\uTorrent\uTorrent.exe => No File
FirewallRules: [{602AAB5E-7597-43FA-A963-B5E529C71B15}] => (Allow) C:\Users\Rappy\AppData\Roaming\uTorrent\uTorrent.exe => No File
FirewallRules: [{5A48EE64-6D5F-405A-A346-51A5949C7838}] => (Allow) 㩃停潲牧浡䘠汩獥⠠㡸⤶獜獹敮浴坜湩潒瑵䑥攮數 => No File
FirewallRules: [{6BCBA42D-6DCD-4B4F-B0E9-24B1692AAED2}] => (Allow) D:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\games\Prince of Persia Sands of Time\PrinceOfPersia.EXE => No File
FirewallRules: [{3E8BD1A8-0310-4C00-8D20-F6D42E01E378}] => (Allow) D:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\games\Prince of Persia Sands of Time\PrinceOfPersia.EXE => No File
FirewallRules: [{80BBF4B2-74A4-40F4-9834-718BA357CA45}] => (Allow) D:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\games\Prince of Persia Sands of Time\POP.EXE => No File
FirewallRules: [{10077182-B73D-41DA-8008-98603F49AF5E}] => (Allow) D:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\games\Prince of Persia Sands of Time\POP.EXE => No File
FirewallRules: [{948EB6F2-A61D-4A2E-90CD-C83DB4FA319A}] => (Allow) D:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\games\Assassin's Creed III\AC3SP.exe => No File
FirewallRules: [{F8E6B91F-6782-4898-9707-039617FAD753}] => (Allow) D:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\games\Assassin's Creed III\AC3SP.exe => No File
FirewallRules: [{2B4CA70D-C95E-46A1-9132-AFB2E5082E3B}] => (Allow) D:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\games\Assassin's Creed III\AC3MP.exe => No File
FirewallRules: [{A234EB1D-B347-48E7-A9C0-F24CFFB43C62}] => (Allow) D:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\games\Assassin's Creed III\AC3MP.exe => No File
FirewallRules: [TCP Query User{B1043692-5079-43C2-8ED6-C302243330CD}D:\users\rappy\desktop\among.us.v2020.9.9s\among us.exe] => (Allow) D:\users\rappy\desktop\among.us.v2020.9.9s\among us.exe => No File
FirewallRules: [UDP Query User{44665EF1-C034-4B3C-8D64-7D7C12B8687D}D:\users\rappy\desktop\among.us.v2020.9.9s\among us.exe] => (Allow) D:\users\rappy\desktop\among.us.v2020.9.9s\among us.exe => No File
C:\Users\Rappy\AppData\Local\46255.exe
EmptyTemp:
C:\Windows\Temp\*.*
End::

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~


Start FRST (FRST64) with Administrator privileges
Press the Fix button. FRST will process the lines copied above from the clipboard.
When finished, a log file Fixlog.txt will pop up and saved in the same location the tool was ran from.

Please copy and paste its contents in your next reply.
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Download and run AdwCleaner

Download AdwCleaner from here and save it to your desktop.

  • run AdwCleaner by clicking on Scan Now
  • when it has finished, leave everything that was found checked, (ticked), then click on Clean and Repair
  • if it asks to reboot, allow the reboot
  • on reboot, click on View Log File; please attach the content of the log to your next reply.
  • ============================================


    Run RogueKiller

    IMPORTANT: Please remove any usb or external drives from the computer and close all running programs before you run this scan!

    Download RogueKiller to your desktop
    • for Windows Vista/7/8/10, right click -> run as administrator, for XP simply double-click on RogueKiller.exe
    • click on Scan then Start under ‘Standard Scan (recommended)’
    • Wait for the scan to complete
    • On completion, the results will be displayed
    • Check every single entry (threat found), and click on the Remove Selected button
    • On completion, the results will be displayed. Click on the Open Report button in the bottom left corner, followed by the Open TXT button (also in the bottom left corner)
    • This will open the report in Notepad. Copy/paste its content in your next reply
    • click on Report
    • click Open and then select text file
    • save the file to your Desktop as RKreport.txt
    • copy/paste the content in your next post
    • NOTE: DO NOT attempt to remove anything that the scan detects –everything that is reported is not necessarily bad
    Please post the contents of the RKreport.txt in your next reply.

Please post these 3 logs when finished.

Thanks Juliet for looking into this issue with me. Here are the logs you requested.

 

I will note that when Chrome started up again, it claimed settings were reset due to another program changing them. The logs show that Honey, Live CSS Editor and Amazon Assistant were deleted, but they were reloaded once Chrome restarted.

I will note that when Chrome started up again, it claimed settings were reset due to another program changing them. The logs show that Honey, Live CSS Editor and Amazon Assistant were deleted, but they were reloaded once Chrome restarted.

When these items originally downloaded they kinda brought in some items considered invasive and unneeded for example:
Amazon Assistant is a browser extension created by Amazon, although displays too many pop-up ads and tracks its users. Amazon Assistant is not technically a virus, the key dilemma lies in its security. The application causes browsing and privacy-related problems. We know this since it can deliver emails with tips on items you've searched for and emails when there have been price drops on something you were looking at.
 
OK,  we've removed quite a bit of junk off your computer.  We're at a stage to check for remnants now.


The below scanner can take a while, please be patient.
After starting the scanner please don't use the computer for anything.
ESET Online Scanner

Download ESET Online Scanner and save it to your desktop.

  • Right-click on esetonlinescanner_enu.exe and select Run as Administrator.
  • When the tool opens, click Get Started.
  • Read and accept the license agreement.
  • At the Welcome to ESET Online Scanner window, click Get Started.
  • Select whether you would like to send anonymous data to ESET.
  • Note: if you see the "Welcome Back to ESET Online Scanner" screen, click Computer Scan > Full Scan.
  • Click on the Full Scan option.
  • Select Enable ESET to detect and remove potentially unwanted applications, then click Start scan.
  • ESET will now begin scanning your computer. This may take some time.
  • When the scan is finished and if threats have been detected, select Save scan log. Save it to your desktop as eset.txt. Click on Continue.
  • ESET Online Scanner may ask if you'd like to turn on the Periodic Scan feature. Click on Continue.
  • On the next screen, you can leave feedback about the program if you wish. Check the box for Delete application data on closing. If you left feedback, click Submit and continue. If not, Close without feedback.
  • Open the scan log on your desktop (eset.txt) and copy and paste its contents into your next reply.

—————————————————

How is the computer now?

3 hours later and this is all that was found. This has been another case of everything's wonky until you report it, then it's fine.

 

Since we started cleanup, the PC has not yet been unresponsive. Though, I have no been running the programs I have been suspicious of.

 

All the reports seemed mostly innocuous. Do you have any other suggestions?

 

Also, I own the premier version of Malware Bytes. Should I stick with this or would you recommend a different software program?

Attachments:

C:\Users\Rappy\AppData\Roaming\BotDeveloper\BotDeveloper.dll    a variant of Win32/GameHack.ERH potentially unsafe application    cleaned by deleting
D:\Users\Rappy\Desktop\Guild Wars Stuff\Developer\BotDeveloper\BotDeveloper.dll    a variant of Win32/GameHack.ERH potentially unsafe application    cleaned by deleting

Hacking Tool, name for hacking tools that intend to enhance certain features or resources while gaming, HackTool.GameHack is often found for download on sites of a dubious nature. Be careful what you download,  many things could be connected.
 
I think having MalwareBytes Premium on your computer is a good secondary source of protection.
 
I can give you a list of free and paid for antivirus you can use along with MalwareBytes if your not satisfied with Windows Defender.

Note: The programs listed below are all free to use or they have some sort of trial. Some of them have a paid version that provides more features, while a lot of other good programs only have a paid version but aren't listed there (such as Kaspersky and ESET Antivirus products).

Antivirus

As for which free versus paid for Antivirus I have to leave this up to you but, I've always stayed with a free version, that use less resources and consumes less time in updating. This is my personal opinion and also with free versions of Antivirus, firewall is not included.
 

Since we started cleanup, the PC has not yet been unresponsive.


I think with all that was found you should be in good shape.
Let's remove tools and quarantine folders.

Use this tool to remove quarantined items:

Please download KpRm by Kernel-panik and save to your Desktop.

  • Click on KpRm.exe to run the tool.

Vista/Windows 7/8/10 users right-click and select Run As Administrator.

  • Put a check mark next to these items:

- Delete tools
- Delete now

  • Click the "Run" button.

[external image: automatic.png]

  • When the tool has finished, it will create and open a log report and delete itself.

~~~~~~~~~~~~~~~~~~~~~~~~~~~

  • Answers to common security questions - Best Practices by quietman7, MVP
  • How Malware Spreads - How did I get infected? by quietman7, MVP
  • Simple and easy ways to keep your computer safe and secure on the Internet by Lawrence Abrams, MVP
  • How to Prevent Malware by miekiemoes, MVP
  • How to backup and restore your data using Cobian Backup by YourHighness
  • Slow Computer/browser? It May Not Be Malware by quietman7, MVP
    • AdBlock is a browser add-on that blocks annoying banners, pop-ups and video ads.
    • [external image: E8I37RF.png]CryptoPrevent places policy restrictions on loading points for ransomware (eg. CryptoWall), helping prevent the execution of malware.
    • [external image: EG85Vjt.png] Malwarebytes Anti-Exploit (MBAE) is designed to prevent zero-day malware from exploiting vulnerable software.
    • [external image: 6YRrgUC.png] Malwarebytes Anti-Malware Premium (MBAM) works in real-time along side your Anti-Virus to prevent malware execution.
    • [external image: jv4nhMJ.png] NoScript is a Firefox add-on that blocks the actions of malicious scripts by using whitelisting and other technology.
    • [external image: 3O8r9Uq.png] Sandboxie isolates programmes of your choice, preventing files from being written to your HDD unless approved by you.
    • [external image: DgW1XL2.png] Secunia PSI will scan your computer for vulnerable software that is outdated, and automatically find the latest update for you.
    • [external image: j1OLIec.png] SpywareBlaster is a form of passive protection, designed to block the actions of malicious websites and tracking cookies.
    • [external image: sHjS79L.png] Unchecky automatically removes checkmarks for bunlded software in programme installers; helping you avoid adware and PUPs.
  • For those interested in how to make a backup of your computer
    https://forums.malwarebytes.com/topic/136226-backup-software/

Before we do that… I am noticing that Chrome takes a good 5-10 seconds to load when first opening and shuts down whenever it feels like it lately (not often, but often enough for me to classify it as an issue). This wasn't the case prior to this forum post. Is there any investigation we can do to figure out why this is happening now?

Unfortunately, uninstalling and reinstalling has not fixed this issue. Chrome seems to be much less stable, crashes a lot, and slow to start initially.

Many times it's a security app interfering.
 
I would like to see a fresh Farbar Recovery Scan log with today's date.

  • Right-Click FRST.exe / FRST64.exe and select [external image: AVOiBNU.jpg] Run as administrator to run the programme.
  • Click Yes to the disclaimer.
  • Ensure the Addition.txt box is checked.
  • Click the Scan button and let the programme run.
  • Upon completion, click OK, then OK on the Addition.txt pop up screen.
  • Two logs (FRST.txt & Addition.txt) will now be open on your Desktop. Copy the contents of both logs and paste in your next reply.

(Scan times will vary from one system to another. Sometimes the scan may appear to hang and you may even see a message that says, Program not responding. Most likely that will be temporary and the scan will resume on its own. It is not unusual for a complete scan to take up to10 minutes or even longer depending on what the scan is finding.)
 

I wanted to pop in quickly and say,  I really wont be able to look over the logs till morning.

 

Whatever is going on I think is software related and I'll need to time do some research which I don't have this evening.

It's possible there is some sort of corrupt profile conflict, security app interference, no idea really but,  what I can see is no sign of malware but we can continue.

Start Farbar Recovery Scan Tool with Administrator privileges
(Right click on the FRST icon and select Run as administrator)

highlight on the text below and select Copy.
beginning with Start:: and finishing with End::
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Highlight the entire content of the quote box below and select Copy.

 

Start::
CloseProcesses:
CreateRestorePoint:
HKLM\Software\…\Authentication\Credential Providers: [{503739d0-4c5e-4cfd-b3ba-d881334f0df2}] ->
HKLM\Software\…\Authentication\Credential Providers: [{D28973E5-8630-41af-8831-50A15FEB396B}] ->
Task: {9D5A8CC4-0991-4823-97A1-49E5790C979F} - \{0A090C47-7E78-0A0B-7E11-780D780F117A} -> No File <==== ATTENTION
Task: {B6B10483-B452-4B1D-8F39-8675C37FAB0C} - \Microsoft\Windows\UNP\RunCampaignManager -> No File <==== ATTENTION
CHR HKLM\…\Chrome\Extension: [ngpampappnmepgilojfohadhhmbhlaek] - C:\Program Files (x86)\Internet Download Manager\IDMGCExt.crx

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~


Start FRST (FRST64) with Administrator privileges
Press the Fix button. FRST will process the lines copied above from the clipboard.
When finished, a log file Fixlog.txt will pop up and saved in the same location the tool was ran from.

Please copy and paste its contents in your next reply.
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Try working with Google Chrome after running the above script.

If it's not working as it should

Add a person or profile

On your computer, open Chrome.
At the top right, click Profile Profile.
Click Add.
Choose a name and a photo (this will add another profile to see if the app will work as it should, confirming existing corrupt profile).
Click Add. A new window will open and ask you to turn on sync.
(Optional) Turn sync on in Chrome with a Google Account for the new profile. Their bookmarks, history, passwords, and other settings will automatically sync.
 

 

Post the log created with FRST and tell me what the computer is doing now.

So sorry. I was on vacation. I have done as you requested. My main Chrome profile was deleted, it seems, and everything popped up on a different profile. I was, however, able to get everything back on my main profile after re-syncing.
 
I got this message the first time trying to open Chrome. http://puu.sh/GJmQf/abd241d0ca.png
 
I closed Chrome and reopened via the start menu, and it did not give the error again. Unfortunately, it did take ~8-10s to open the blank homepage.
 

Attachments:

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI