Slow HP Pavilion Gaming Laptop, Already addressed startup services, scheduled Windows Defender, Ran CCleaner, Upgraded to 32gb RAM, Updated Drivers

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • Peccant
    PCHF Member
    • Dec 2022
    • 28

    #1

    Slow HP Pavilion Gaming Laptop, Already addressed startup services, scheduled Windows Defender, Ran CCleaner, Upgraded to 32gb RAM, Updated Drivers

    Hi folks. Am I infected? I am running out of other options of reasons my computer is so slow. The latency is affecting not only software, but my WiFi is slow to load as well.

    The Computer:
    Processor AMD Ryzen 5 4600H with Radeon Graphics 3.00 GHz
    Installed RAM 32.0 GB (31.4 GB usable)
    System type 64-bit operating system, x64-based processor
    Edition Windows 11 Home
    Version 22H2
    Installed on ‎2022-‎12-‎05
    OS build 22621.963
    Experience Windows Feature Experience Pack 1000.22638.1000.0

    Already addressed startup services, scheduled Windows Defender, Ran CCleaner, Upgraded to 32gb RAM from 8gb, Updated Drivers with Driver Easy, temporarily disabled Windows Defender, ran BitDefender, uninstalled apps and programs not using, uninstalled any extensions on Chrome and Edge, reduced all graphics dsiplay settings to work for performance over appearance.

    Task manager tells me my CPU is between 1-5% (never saw it higher), my Memory is now running between 15-20%, Disk around 1% at the highest, and Network is low, often 0%.

    Largest memory users other than Chrome and the software I’m currently using is mysqld, Desktop Windows Manager, Antimalware Service Executable, HP System Event Utility, Phone Link, NVIDIA Container (in descending order of use, but none using over 200MB).

    I have an HDMI cord running to second monitor, but running without the monitor does not speed up the computer.

    I’m now wondering if BitDefender and CCleaner and Windows Defender are missing some Malware or something. I’ve read every forum I could find relevant and tried so many of the fixes without result that I’m thinking it has to be Malware.

    I will note: when I increased the RAM it made a difference, but not enough to make the computer useable.

    As for software that I am using: I don’t have any games installed whatsoever, despite the gaming laptop. I run Sage 50 Accounting. Sometimes I run Adobe InDesign, Illustrator, or Photoshop, but not often, and I made sure Adobe Creative Cloud and all auto updaters were not running in the background. I know Chrome uses a lot of memory, but even when I shut down Chrome and then force the task to end, the computer doesn’t get any faster.

    Any and all ideas would be appreciated. And if it’s not malware, I’d love to have this thread moved to an appropriate forum for this type of stuff.

    Thanks in advance!
  • Malnutrition
    PCHF Moderator
    • Jul 2016
    • 7041

    #2
    Please download the FRST 32 bit or FRST 64bit version to suit your operating system. It is important FRST is downloaded to your desktop.
    If you are unsure if your operating system is 32 or 64 Bit please go HERE.
    Once downloaded right click the FRST desktop icon and select “Run as administrator” from the menu
    If you receive any security warnings, or the User Account Control warning opens at any time whilst using FRST you can safely allow FRST to proceed.
    FRST will open with two dialogue boxes, accept the disclaimer.
    [ol]
    [li]Accept the default whitelist options,[/li][li]If the additions.txt options box is not checked please select it.[/li][li]Then select Scan[/li][li]Frst will take a few minutes to scan your computer, and when finished will produce two log files on your desktop, FRST.txt, and Addition.txt. They will display immediately on the desktop, but can be reopened later as a notepad file.[/li][/ol]

    [IMG alt=“2016-08-12_152002.jpg”]https://pchelpforum.net/attachments/...52002-jpg.797/

    Please Attach the contents of these logs in your next post for review by our Security Team[/IMG]

    Comment

    • Peccant
      PCHF Member
      • Dec 2022
      • 28

      #3
      Thanks @Malnutrition Here are the results:

      Comment

      • Malnutrition
        PCHF Moderator
        • Jul 2016
        • 7041

        #4
        I’ll have a look at the logs when I return home in about 6 hours.

        Adware Cleaner

        [ul]
        [li]Download AdwCleaner and save it to your Desktop[/li][li]Right-click on AdwCleaner.exeand select, Run as Administrator[/li][li]Accept the EULA (I accept), then click on Scan Now[/li][li]Let the scan complete[/li][li]Once the scan completes, make sure that every item listed in the different tabs is checked and click on the Clean & Repair button[/li][li]Subsequently you may be asked to Run Basic Repair. This is optional. I would suggest holding off on this for now.[/li][li]Once the cleaning process is complete, AdwCleaner will ask you to restart your computer[/li][li]Close all other open windows and allow it to restart[/li][li]After the restart, Notepad will open with the AdwCleaner cleaning log[/li][li]Please Attach the contents of that log into your next reply to me[/li][/ul]








        Download Malwarebytes v.4 . Install and run.

        [ul]
        [li]Once the MBAM dashboard opens, click on Settings (gear icon).[/li][li]Click on Security tab and make sure that all four Scan options are enabled.[/li][li]Close Settings and click on the Scan button on the dashboard.[/li][li]Once the scan is completed make sure you have it quarantine any detections it finds.[/li][li]If no detections were found click on the Save results drop-down, then the Export to TXT button and save the file as a Text file to your desktop.[/li][li]If there were detections then once the quarantine has completed click on the View report button, then click the Export drop-down, then the Export to TXT button, and save the file as a Text file to your desktop or other location you can find and attach that log on your next reply.[/li][li]If the computer restarted to quarantine you can access the logs from the Detection History, then the History tab. Highlight the most recent scan and double-click to open it. Then click the Export drop-down, then the Export to TXT button, and save the file as a Text file to your desktop or other location you can find and include that log on your next reply.[/li][/ul]

        Comment

        • Peccant
          PCHF Member
          • Dec 2022
          • 28

          #5
          AdwCleaner download link seems to be down.
          Attached are the MBAM logs. No quarantining required.

          Comment

          • Malnutrition
            PCHF Moderator
            • Jul 2016
            • 7041

            #6
            Working link.

            AdwCleaner is a free anti-malware removal tool designed to eliminate: Adware (ads software) PUP/LPI (Potentially Unwanted Programs) Toolbars Hijackers (browser homepage hijackers) SpywareAdwCleaner quickly scans and removes adw...

            Comment

            • Malnutrition
              PCHF Moderator
              • Jul 2016
              • 7041

              #7
              @Peccant


              Uninstall Useless programs!
              Hit the windows key and R at the same time.
              Type [COLOR=rgb(184, 49, 47)]appwiz.cpl hit ok.
              Uninstall these programs below.

              [COLOR=rgb(147, 101, 184)]Bonjour
              Driver Easy 5.7.3


              Download and run [COLOR=rgb(147, 101, 184)]Startup lite.


              Copy the content of the code box below.
              [COLOR=rgb(184, 49, 47)]Do not copy the word code!!!
              Right Click FRST and run as Administrator.
              Click Fix once (!) and wait. The program will create a log file (Fixlog.txt).
              Attach it to your next message.
              Code:
              Start::
              CloseProcesses:
              SystemRestore: On
              CreateRestorePoint:
              RemoveProxy:
              HKLM\Software\...\Authentication\Credential Providers: [{C885AA15-1764-4293-B82A-0586ADD46B35}] ->
              GroupPolicy: Restriction ? <==== ATTENTION
              Policies: C:\ProgramData\NTUSER.pol: Restriction <==== ATTENTION
              Task: {172E3960-78E7-4F7E-89AD-CBB249C1DC05} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1552376 2022-09-26] (Adobe Inc. -> Adobe Inc.)
              Task: {59F6A7E4-C206-404D-932A-41B60C3A100E} - System32\Tasks\Driver Easy Scheduled Scan => C:\Program Files\Easeware\DriverEasy\DriverEasy.exe [3995016 2022-08-16] (Easeware Technology Limited -> Easeware)
              C:\Program Files\Easeware
              Task: {CE774C98-9860-4FCE-BE69-EA3237BB5C7A} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe [684976 2022-12-09] (Piriform Software Ltd -> Piriform)
              Task: C:\WINDOWS\Tasks\CCleanerCrashReporting.job => C:\Program Files\CCleaner\CCleanerBugReport.exe
              Task: C:\WINDOWS\Tasks\Driver Easy Scheduled Scan.job => C:\Program Files\Easeware\DriverEasy\DriverEasy.exe
              2022-12-16 09:32 - 2022-12-29 09:25 - 000003290 _____ C:\WINDOWS\system32\Tasks\CCleaner Update
              2022-12-16 09:32 - 2022-12-29 09:24 - 000003808 _____ C:\WINDOWS\system32\Tasks\CCleanerSkipUAC - Mark Wainman
              2022-12-16 09:32 - 2022-12-29 09:24 - 000003410 _____ C:\WINDOWS\system32\Tasks\CCleanerCrashReporting
              2022-12-15 09:34 - 2022-12-16 10:28 - 000000452 _____ C:\WINDOWS\Tasks\Driver Easy Scheduled Scan.job
              2022-12-15 09:34 - 2022-12-16 09:43 - 000003640 _____ C:\WINDOWS\system32\Tasks\Driver Easy Scheduled Scan
              2022-12-07 16:21 - 2022-12-07 16:21 - 000427452 _____ C:\ProgramData\cl.uninstall.1670444340.bdinstall.v2.bin
              2022-12-07 14:09 - 2022-12-07 14:09 - 000648948 _____ C:\ProgramData\cl.1670436053.bdinstall.v2.bin
              2022-12-07 14:09 - 2022-12-07 14:09 - 000113248 _____ C:\ProgramData\cl.kit.1670436044.bdinstall.v2.bin
              2022-12-07 14:08 - 2022-12-07 14:08 - 000000000 ____D C:\ProgramData\48C4687D-9760-4F5B-BAB3-60351B0841E4
              2022-12-07 14:05 - 2022-12-07 14:05 - 000000000 ____D C:\ProgramData\BDLogging
              2022-12-07 13:59 - 2022-12-07 13:59 - 000156488 _____ C:\ProgramData\agent.1670435966.bdinstall.v2.bin
              2022-12-07 13:59 - 2022-12-07 13:59 - 000000000 ____D C:\Users\Mark Wainman\AppData\Local\Bitdefender
              ContextMenuHandlers1: [AccExt] -> [CC]{2A118EB5-5797-4F5E-8B3D-F4ECBA3C98E4} =>  -> No File
              ContextMenuHandlers1: [Adobe.Acrobat.ContextMenu] -> [CC]{A6595CD1-BF77-430A-A452-18696685F7C7} =>  -> No File
              ShortcutWithArgument: C:\Users\Mark Wainman\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\69639df789022856\R. Mark - Chrome.lnk -> C:\Program Files\Google\Chrome\Application\chrome.exe (Google LLC) -> --profile-directory="Profile 1"
              SearchScopes: HKLM -> {0C3E81FF-E85C-44C4-ACC7-EAE68F6F769C} URL = hxxp://www.amazon.ca/s/ref=azs_osd_ieaca?ie=UTF-8&tag=hp-ca2-vsb-20&link%5Fcode=qs&index=aps&field-keywords={searchTerms}
              SearchScopes: HKLM-x32 -> {0C3E81FF-E85C-44C4-ACC7-EAE68F6F769C} URL = hxxp://www.amazon.ca/s/ref=azs_osd_ieaca?ie=UTF-8&tag=hp-ca2-vsb-20&link%5Fcode=qs&index=aps&field-keywords={searchTerms}
              SearchScopes: HKU\S-1-5-21-1586263983-1164605689-3317866451-1001 -> {0C3E81FF-E85C-44C4-ACC7-EAE68F6F769C} URL = hxxp://www.amazon.ca/s/ref=azs_osd_ieaca?ie=UTF-8&tag=hp-ca2-vsb-20&link%5Fcode=qs&index=aps&field-keywords={searchTerms}
              C:\WINDOWS\system32\drivers\etc\hosts
              Hosts:
              FirewallRules: [{44312095-4CE8-4959-9ED4-9FEE7A719200}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe (Apple Inc. -> Apple Inc.)
              FirewallRules: [{BF54DB1C-4AFC-4EA6-AE3D-689C2EFEA83D}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe (Apple Inc. -> Apple Inc.)
              FirewallRules: [{292FE63E-F715-41A7-9365-507F83638610}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc. -> Apple Inc.)
              FirewallRules: [{26397D6A-590C-4501-8E12-22569CFA14FD}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc. -> Apple Inc.)
              FirewallRules: [{26967F5F-FC54-487F-8AE6-0C138A6CA4CD}] => (Allow) C:\Program Files\Easeware\DriverEasy\DriverEasy.exe (Easeware Technology Limited -> Easeware)
              FirewallRules: [{B605B7D0-BDDE-4284-AF56-9F38A3090D3A}] => (Allow) C:\Program Files (x86)\Winsim\ConnectionManager\MySqlBinary\5.0.38\mysql\mysqld-nt.exe => No File
              FirewallRules: [{1FA42B39-7770-4D8B-B8FB-C9BF7D28E033}] => (Allow) C:\Program Files (x86)\Winsim\ConnectionManager\MySqlBinary\5.0.38\mysql\mysqld-nt.exe => No File
              Folder: C:\WINDOWS\Setup
              Folder: C:\WINDOWS\system32\WebThreatDefSvc
              VirusTotal: C:\program files (x86)\remote mouse\remotemouse.exe
              VirusTotal: C:\Program Files (x86)\LMIR0CCBA001.tmp_r.bat
              VirusTotal: C:\Program Files (x86)\LMIR0CCBA001.tmp.bat
              VirusTotal: C:\windows\system32\SCN2PM.dll
              cmd: netsh winsock reset catalog
              cmd: netsh int ip reset C:\resettcpip.txt
              cmd: net stop bits
              Move: C:\ProgramData\Microsoft\Network\Downloader\qmgr*.db C:\ProgramData\Microsoft\Network\Downloader\qmgr*.db.old
              cmd: net start bits
              cmd:  bitsadmin /list /allusers
              CMD: "%WINDIR%\SYSTEM32\lodctr.exe /R"
              CMD: "%WINDIR%\SysWOW64\lodctr.exe /R"
              CMD: "C:\Windows\SYSTEM32\lodctr.exe /R"
              CMD: "C:\Windows\SysWOW64\lodctr.exe /R"
              CMD: del /f /s /q %windir%\prefetch\*.*
              CMD: del /s /q C:\Windows\SoftwareDistribution\download\*.*
              CMD: del /s /q "%userprofile%\AppData\Local\Google\Chrome\User Data\Default\Cache\*.*"
              CMD: del /s /q "%userprofile%\AppData\Local\temp\*.*"
              CMD: ipconfig /flushdns
              C:\Windows\Temp\*.*
              C:\WINDOWS\system32\*.tmp
              C:\WINDOWS\syswow64\*.tmp
              ExportKey: HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions
              emptytemp:
              Reboot:
              End::

              [/COLOR][/COLOR][/COLOR][/COLOR]

              Comment

              • Peccant
                PCHF Member
                • Dec 2022
                • 28

                #8
                Completed all tasks listed except the code I was to copy. I do not know where to put that code once I copy it.

                Attached Fixlog.

                Comment

                • Malnutrition
                  PCHF Moderator
                  • Jul 2016
                  • 7041

                  #9
                  The code you copied was what allowed you to run the fix with FRST

                  I’ll have to check the logs when I return from work, just let me know how the computer is running and also run this tool for me, it is similar to FRST but checks in different areas. When I return home I’ll check logs and provide another fix for you.

                  Download ZHP Suite to your desktop.
                  Right Click Run as admin.
                  Hit the scanner button.
                  Once it is complete a file name ZHPdiag.txt will be on your desktop.
                  Attach it.

                  If you can, run adware cleaner for me, just to clean up rubbish, if you have never ran it, it’s good at cleaning useless crap from a machine.

                  Comment

                  • Peccant
                    PCHF Member
                    • Dec 2022
                    • 28

                    #10
                    Laptop performance is good so far, yes. I am not in my office for a week with the setup I had before (vacation), but I have opened the Sage 50 Canada Accounting software and it seems to be working much more efficiently. I’m not experiencing much lag at all. Have the log files suggested things have been removed, and if so, was it Malware, or just HP prepackaged stuff, etc?

                    I’ve attached the most recent log files.

                    Comment

                    • Malnutrition
                      PCHF Moderator
                      • Jul 2016
                      • 7041

                      #11
                      @Peccant



                      It was just an accumulation of crap, that happens over time, left over files and such from previously installed programs that were still running. I like to remove trash as I look for malware…Last set of fixes below.



                      As a part of the process I sent the file [COLOR=rgb(184, 49, 47)]C:\program files (x86)\remote mouse\remotemouse.exe to Virus Total, here is the result.=> Click here to see. Up to you to keep it, sometimes these scanners get things wrong. If you trust this software then keep it.




                      Copy the content of the code box below.
                      [COLOR=rgb(184, 49, 47)]Do not copy the word code!!!
                      Right Click FRST and run as Administrator.
                      Click Fix once (!) and wait. The program will create a log file (Fixlog.txt).
                      Attach it to your next message.

                      [ICODE] Start:: CloseProcesses: SystemRestore: On CreateRestorePoint: DeleteValue: HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Exp lorer\StartupApproved\Run|GoogleChromeAutoLaunch_B 3DDF419224FD7F2BAC71AA016515291 DeleteValue: HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Exp lorer\StartupApproved\Run|btweb DeleteValue: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Exp lorer\StartupApproved\Run|Bdagent DeleteValue: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Exp lorer\StartupApproved\Run|CL-26-5B9487A6-54CF-4096-80F8-4E750D003AA0 DeleteKey: HKLM\SOFTWARE\McAfee DeleteKey: HKLM\SOFTWARE\WOW6432Node\McAfee C:\Program Files\McAfee C:\ProgramData\McAfee DeleteKey: HKLM\SOFTWARE\WOW6432Node\Bitdefender Agent C:\ProgramData\Bitdefender Agent C:\WINDOWS\System32\Config\systemprofile\AppData\L ocal\Bitdefender DeleteKey: HKLM\SOFTWARE\WOW6432Node\Lavasoft DeleteKey: HKCU\SOFTWARE\Lavasoft C:\ProgramData\Lavasoft C:\Users\Mark Wainman\AppData\Local\Lavasoft C:\ProgramData\McInstTemp0128501618496141 C:\Users\Mark Wainman\AppData\Local\Adaware C:\Users\Mark Wainman\AppData\Local\Lavasoft ExportKey: HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Run ExportKey: HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\RunOnce ExportKey: HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\StartupApproved\Run ExportKey: HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\StartupApproved\Run32 ExportKey: HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\StartupApproved\StartupFolder cmd: del /s /q "%userprofile%\AppData\Local\Google\Chrome\Use r Data\Default\Cache\*.*" cmd: del /s /q "%userprofile%\AppData\Local\Microsoft\Edge\Us er Data\Default\Cache\*.*" cmd: del /s /q "%userprofile%\AppData\Local\Opera Software\Opera Stable\Cache\Cache_Data\*.*" cmd: DISM.exe /Online /Cleanup-image /Restorehealth cmd: sfc /scannow cmd: winmgmt /salvagerepository cmd: winmgmt /verifyrepository Folder: C:\Windows\System32\Tasks emptytemp: Reboot: End:: [/ICODE]


                      Security Check Scan.

                      [ul]
                      [li]Download Security Check to your desktop.[/li][li]Right click it run as administrator.[/li][li]When the program completes, the tool will automatically open a log file.[/li][li]Please [COLOR=rgb(184, 49, 47)]Copy and paste that log here in your next post.[/li][li]There will be items listed in red when you post this log, those items need to be updated.[/li][/ul]


                      Let me know if there is any questions, and we can wrap this up if you wish. [/COLOR][/COLOR][/COLOR]

                      Comment

                      • Malnutrition
                        PCHF Moderator
                        • Jul 2016
                        • 7041

                        #12
                        @Peccant How are you moving along with the instructions, can you give us an update please.

                        Comment

                        • Peccant
                          PCHF Member
                          • Dec 2022
                          • 28

                          #13
                          Sorry, holiday and family visits got in the way. Attached is the log from FRST. Laptop seems to be performing properly. I really appreciate this help. It’ll be a life-saver when I’m back in the office. I will put it to the full test tomorrow when I run Sage Accounting and my other items at the same time.

                          SecurityCheck by glax24 & Severnyj v.1.4.0.54 [06.12.21]
                          WebSite: www.safezone.cc
                          DateLog: 02.01.2023 17:10:24
                          Path starting: C:\Users\Mark Wainman\AppData\Local\Temp\SecurityCheck\SecurityC heck.exe
                          Log directory: C:\SecurityCheck
                          IsAdmin: True
                          User: Mark Wainman
                          VersionXML: 10.35is-31.12.2022


                          Windows 11(6.3.22621) (x64) Core Release: 22H2 Lang: English(0409)
                          Installation date OS: 05.12.2022 22:15:06
                          LicenseStatus: Windows(R), Core edition The machine is permanently activated.
                          LicenseStatus: Office 16, Office16O365BusinessR_Grace edition Windows is in Notification mode
                          Boot Mode: Normal
                          Default Browser: C:\Program Files\Google\Chrome\Application\chrome.exe
                          SystemDrive: C: FS: [NTFS] Capacity: [237.5 Gb] Used: [160.5 Gb] Free: [77 Gb]
                          ------------------------------- [ Windows ] -------------------------------
                          User Account Control enabled (Level 3)
                          Security Center (wscsvc) - The service is running
                          Remote Registry (RemoteRegistry) - The service has stopped
                          SSDP Discovery (SSDPSRV) - The service is running
                          Remote Desktop Services (TermService) - The service has stopped
                          Windows Remote Management (WS-Management) (WinRM) - The service has stopped
                          ------------------------------ [ MS Office ] ------------------------------
                          Microsoft Office 2007 v.12.0.4518.1031
                          ---------------------------- [ Antivirus_WMI ] ----------------------------
                          Malwarebytes (enabled and up to date)
                          Windows Defender (disabled and up to date)
                          --------------------------- [ FirewallWindows ] ---------------------------
                          Windows Defender Firewall (mpssvc) - The service is running
                          ---------------------- [ AntiVirusFirewallInstall ] -----------------------
                          Malwarebytes version 4.5.19.229 v.4.5.19.229
                          --------------------------- [ OtherUtilities ] ----------------------------
                          Microsoft 365 Apps for business - en-us v.16.0.15831.20208
                          Microsoft 365 - en-us v.16.0.15831.20208
                          Microsoft 365 - fr-fr v.16.0.15831.20208
                          NVIDIA GeForce Experience 3.20.2.34 v.3.20.2.34 Warning! Download Update
                          Microsoft Office Access database engine 2007 (English) v.12.0.4518.1031 Warning! This software is no longer supported.
                          ------------------------------- [ Backup ] --------------------------------
                          Microsoft OneDrive v.22.238.1114.0002
                          -------------------------- [ IMAndCollaborate ] ---------------------------
                          Zoom v.5.11.4 (7185) Warning! Download Update
                          -------------------------------- [ Media ] --------------------------------
                          VLC media player v.3.0.18
                          --------------------------- [ AdobeProduction ] ---------------------------
                          Adobe Acrobat (64-bit) v.22.003.20282
                          Adobe Creative Cloud v.5.9.0.372
                          ------------------------------- [ Browser ] -------------------------------
                          Google Chrome v.108.0.5359.99 Warning! Download Update
                          Microsoft Edge v.108.0.1462.54
                          ------------------ [ AntivirusFirewallProcessServices ] -------------------
                          C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe v.4.0.0.1403
                          Malwarebytes Service (MBAMService) - The service is running
                          C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe v.3.2.0.1161
                          Microsoft Defender Antivirus Service (WinDefend) - The service has stopped
                          Microsoft Defender Antivirus Network Inspection Service (WdNisSvc) - The service has stopped
                          ---------------------------- [ UnwantedApps ] -----------------------------
                          CCleaner v.6.07 Warning! Suspected demo version of anti-spyware, driver updater or optimizer. If this program is not familiar to you it is recommended to uninstall it and execute PC scanning using Malwarebytes Anti-Malware. Possible you became a victim of fraud or social engineering. Computer experts no longer recommend this program.
                          ----------------------------- [ End of Log ] ------------------------------

                          Comment

                          • Malnutrition
                            PCHF Moderator
                            • Jul 2016
                            • 7041

                            #14
                            You can disable all of the scheduled task listed n the code box below, they are not really needed. You can disable scheduled task with CCleaner which you have installed, or download Autoruns by clicking here.

                            If you use One Drive, then leave those entries alone. If you do not use it, then disable/uninstall it.


                            I suggest the following to increase security and privacy!
                            Ublock Origin
                            O&O Shutup Ten
                            O&O App Buster


                            Code:
                            C:\Windows\System32\Tasks\Adobe Creative Cloud
                            C:\Windows\System32\Tasks\AdobeGCInvoker-1.0
                            C:\Windows\System32\Tasks\CCleanerCrashReporting
                            C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
                            C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
                            C:\Windows\System32\Tasks\MicrosoftEdgeUpdateTaskMachineCore
                            C:\Windows\System32\Tasks\MicrosoftEdgeUpdateTaskMachineUA
                            C:\Windows\System32\Tasks\NvBatteryBoostCheckOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
                            C:\Windows\System32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
                            C:\Windows\System32\Tasks\NVIDIA GeForce Experience
                            C:\Windows\System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
                            C:\Windows\System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
                            C:\Windows\System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
                            C:\Windows\System32\Tasks\NvTmRep_CrashReport1_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
                            C:\Windows\System32\Tasks\NvTmRep_CrashReport2_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
                            C:\Windows\System32\Tasks\NvTmRep_CrashReport3_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
                            C:\Windows\System32\Tasks\NvTmRep_CrashReport4_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
                            C:\Windows\System32\Tasks\OneDrive Reporting Task-S-1-5-21-1586263983-1164605689-3317866451-1001
                            C:\Windows\System32\Tasks\OneDrive Reporting Task-S-1-5-21-1586263983-1164605689-3317866451-1004
                            C:\Windows\System32\Tasks\OneDrive Standalone Update Task-S-1-5-21-1586263983-1164605689-3317866451-1001
                            C:\Windows\System32\Tasks\OneDrive Standalone Update Task-S-1-5-21-1586263983-1164605689-3317866451-1004
                            C:\Windows\System32\Tasks\OneDrive Standalone Update Task-S-1-5-21-1586263983-1164605689-3317866451-500
                            C:\Windows\System32\Tasks\OneDrive Standalone Update Task-S-1-5-21-1785876445-2331437723-178080249-500
                            C:\Windows\System32\Tasks\OneDrive Standalone Update Task-S-1-5-21-3948449565-1973883119-2500807518-500
                            C:\Windows\System32\Tasks\OneDrive Standalone Update Task-S-1-5-21-913737145-1433743232-4147240673-500
                            C:\Windows\System32\Tasks\Hewlett-Packard
                            C:\Windows\System32\Tasks\Hewlett-Packard\HP Diagnostics
                            C:\Windows\System32\Tasks\Hewlett-Packard\HP Diagnostics\ABO
                            C:\Windows\System32\Tasks\Hewlett-Packard\HP Diagnostics\BatteryStatusError
                            C:\Windows\System32\Tasks\Hewlett-Packard\HP Diagnostics\BatteryStatusTest
                            C:\Windows\System32\Tasks\Hewlett-Packard\HP Diagnostics\BCF
                            C:\Windows\System32\Tasks\Hewlett-Packard\HP Diagnostics\BHM1
                            C:\Windows\System32\Tasks\Hewlett-Packard\HP Diagnostics\BHM2
                            C:\Windows\System32\Tasks\Hewlett-Packard\HP Diagnostics\LaunchUI
                            C:\Windows\System32\Tasks\Hewlett-Packard\HP Diagnostics\ShowUI
                            C:\Windows\System32\Tasks\Hewlett-Packard\HP Diagnostics\SmartCheckError
                            C:\Windows\System32\Tasks\Hewlett-Packard\HP Diagnostics\Uninstall-BatteryStatusTest
                            C:\Windows\System32\Tasks\Hewlett-Packard\HP Support Assistant
                            C:\Windows\System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Assistant Update Notice
                            C:\Windows\System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Report
                            C:\Windows\System32\Tasks\Hewlett-Packard\HP Support Assistant\WarrantyChecker
                            C:\Windows\System32\Tasks\Hewlett-Packard\HP Support Assistant\WarrantyChecker_DeviceScan
                            C:\Windows\System32\Tasks\HP
                            C:\Windows\System32\Tasks\HP\Consent Manager Launcher
                            C:\Windows\System32\Tasks\HP\HP Support Assistant
                            C:\Windows\System32\Tasks\Microsoft\Windows\Customer Experience Improvement Program
                            C:\Windows\System32\Tasks\Microsoft\Windows\Customer Experience Improvement Program\Consolidator
                            C:\Windows\System32\Tasks\Microsoft\Windows\Customer Experience Improvement Program\UsbCeip



                            You can if you wish, disable useless services with this batch file. Open a notepad and copy the content of the code box below, paste into open notepad and save it to your desktop as clean.bat then right click on clean.bat and run as admin.

                            Note: You should allow the n batch file to complete, it may take some time and some assistance on your part!! Once it reboots your machine that is when it is done.

                            [COLOR=rgb(184, 49, 47)]Do not copy the word Code:
                            Code:
                            @echo off
                            wmic /Namespace:\\root\default Path SystemRestore Call Enable "%SystemDrive%"
                            WMIC /Namespace:\\root\default Path SystemRestore Call CreateRestorePoint "BatchRestorePoint", 100, 10
                            powercfg.exe /setactive 381b4222-f694-41f0-9685-ff5bb260df2e
                            %WINDIR%\SYSTEM32\lodctr.exe /R
                            %WINDIR%\SysWOW64\lodctr.exe /R
                            C:\Windows\SYSTEM32\lodctr.exe /R
                            C:\Windows\SysWOW64\lodctr.exe /R
                            del /s /q "%userprofile%\AppData\Local\temp\*.*"
                            del /f /s /q %systemdrive%\*.tmp
                            del /f /s /q %windir%\prefetch\*.*
                            ipconfig /flushdns
                            ipconfig /registerdns
                            sc stop sysmain
                            sc config sysmain start= disabled
                            sc stop DiagTrack
                            sc config DiagTrack start= disabled
                            sc stop dmwappushservice
                            sc config dmwappushservice start= disabled
                            sc stop WSearch
                            sc config WSearch start= disabled
                            sc stop lfsvc
                            sc config lfsvc start= disabled
                            del /s /q %ProgramData%\Microsoft\Diagnosis\ETLLogs\AutoLogger\AutoLogger-Diagtrack-Listener.etl
                            echo "" > %ProgramData%\Microsoft\Diagnosis\ETLLogs\AutoLogger\AutoLogger-Diagtrack-Listener.etl
                            pause
                            shutdown -r
                            Exit /B


                            [COLOR=rgb(147, 101, 184)]If there is nothing else, we can close this thread and mark it solved?[/COLOR][/COLOR]

                            Comment

                            • Peccant
                              PCHF Member
                              • Dec 2022
                              • 28

                              #15
                              Thank you again, yes I am satisfied that this issue is resolved. Amazing support!

                              Comment

                              Working...