Re-Open Issue with Laptop. Was resolved, but back to poor performance. Did something reinstall?

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • Peccant
    PCHF Member
    • Dec 2022
    • 28

    #1

    Re-Open Issue with Laptop. Was resolved, but back to poor performance. Did something reinstall?

    Hi @Malnutrition. Our previously resolved case of the slow HP Pavilion Gaming Laptop seems to have re-occured when I returned to the office after vacation. I’m now wondering if there is something sitting on one of my three external HD backups that, when I plugged back in, whatever was slowing my computer before may have re-installed? I don’t even know if that is a thing, but where we had the laptop working like a rocket, it’s now back to slow performance to the point I can barely use Sage 50 Accounting to post entries.

    Should this be re-opened here or should I try a different forum board?
  • Malnutrition
    PCHF Moderator
    • Jul 2016
    • 7041

    #2
    We can check here first, then move the thread if needed.

    Download Autologger to your desktop.
    [COLOR=rgb(184, 49, 47)]Disable your Anitivirus/Defender prior to running.
    [ul]
    [li]Unzip it there. – If you are unsure how to unzip a program, then use ---- http://www.7-zip.org/ ----[/li][li]Right click Autologger and [COLOR=rgb(184, 49, 47)]run as administrator. (Xp user double click)[/li][li]AVZ4 will open and scan your machine, allow this to complete.[/li][li]Upload [COLOR=rgb(184, 49, 47)]Collectionlog.zip to your next reply.[/li][/ul]


    Please download the FRST 32 bit or FRST 64bit version to suit your operating system. It is important FRST is downloaded to your desktop.
    If you are unsure if your operating system is 32 or 64 Bit please go HERE.
    Once downloaded right click the FRST desktop icon and select “Run as administrator” from the menu
    If you receive any security warnings, or the User Account Control warning opens at any time whilst using FRST you can safely allow FRST to proceed.
    FRST will open with two dialogue boxes, accept the disclaimer.

    [ol]
    [li]Accept the default whitelist options,[/li][li]If the additions.txt options box is not checked please select it.[/li][li]Then select Scan[/li][li]Frst will take a few minutes to scan your computer, and when finished will produce two log files on your desktop, FRST.txt, and Addition.txt. They will display immediately on the desktop, but can be reopened later as a notepad file.[/li][/ol]
    Code:
        [IMG alt="2016-08-12_152002.jpg"]https://pchelpforum.net/attachments/2016-08-12_152002-jpg.797/
    Please Attach the contents of these logs in your next post for review by our Security Team[/COLOR][/COLOR][/COLOR]

    Comment

    • Peccant
      PCHF Member
      • Dec 2022
      • 28

      #3
      Thanks a lot. Here are the logs.

      Comment

      • Malnutrition
        PCHF Moderator
        • Jul 2016
        • 7041

        #4
        Disable these scheduled task, as they only eat resources, you can update these programs manually.
        Download TaskSchedulerView (64-bit) Unzip it to the desktop.
        Right click and run as admin!!
        Seek out and disable each of the task below.
        [COLOR=rgb(147, 101, 184)]Also, disable anything else you see that is not of use to you.

        [ICODE]C:\WINDOWS\system32\tasks\Adobe Creative Cloud C:\WINDOWS\system32\tasks\AdobeGCInvoker-1.0 C:\WINDOWS\system32\tasks\GoogleUpdateTaskMachineC ore C:\WINDOWS\system32\tasks\GoogleUpdateTaskMachineU A C:\WINDOWS\system32\tasks\MicrosoftEdgeUpdateTaskM achineCore C:\WINDOWS\system32\tasks\MicrosoftEdgeUpdateTaskM achineUA C:\WINDOWS\system32\tasks\NvDriverUpdateCheckDaily _\NvContainerDriverUpdateCheck.log C:\WINDOWS\system32\tasks\NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} - C:\WINDOWS\system32\tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} C:\WINDOWS\system32\tasks\NvProfileUpdaterDaily_{B 2FE1952-0186-46C3-BAEC-A80AA35AC5B8} C:\WINDOWS\system32\tasks\NvProfileUpdaterOnLogon_ {B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} C:\WINDOWS\system32\tasks\NvTmRep_CrashReport1_{B2 FE1952-0186-46C3-BAEC-A80AA35AC5B8} C:\WINDOWS\system32\tasks\NvTmRep_CrashReport2_{B2 FE1952-0186-46C3-BAEC-A80AA35AC5B8} C:\WINDOWS\system32\tasks\NvTmRep_CrashReport3_{B2 FE1952-0186-46C3-BAEC-A80AA35AC5B8} C:\WINDOWS\system32\tasks\NvTmRep_CrashReport4_{B2 FE1952-0186-46C3-BAEC-A80AA35AC5B8} C:\WINDOWS\system32\tasks\OneDrive Reporting Task-S-1-5-21-1586263983-1164605689-3317866451-1001 C:\WINDOWS\system32\tasks\OneDrive Reporting Task-S-1-5-21-1586263983-1164605689-3317866451-1004 C:\WINDOWS\system32\tasks\OneDrive Standalone Update Task-S-1-5-21-1586263983-1164605689-3317866451-1001 C:\WINDOWS\system32\tasks\OneDrive Standalone Update Task-S-1-5-21-1586263983-1164605689-3317866451-1004 C:\WINDOWS\system32\tasks\OneDrive Standalone Update Task-S-1-5-21-1586263983-1164605689-3317866451-500 C:\WINDOWS\system32\tasks\OneDrive Standalone Update Task-S-1-5-21-1785876445-2331437723-178080249-500 C:\WINDOWS\system32\tasks\OneDrive Standalone Update Task-S-1-5-21-3948449565-1973883119-2500807518-500 C:\WINDOWS\system32\tasks\OneDrive Standalone Update Task-S-1-5-21-913737145-1433743232-4147240673-500 C:\WINDOWS\system32\tasks\Hewlett-Packard\HP Support Assistant\HP Support Assistant Update Notice - C:\WINDOWS\system32\tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Report C:\WINDOWS\system32\tasks\Hewlett-Packard\HP Support Assistant\WarrantyChecker C:\WINDOWS\system32\tasks\Hewlett-Packard\HP Support Assistant\WarrantyChecker_DeviceScan - C:\WINDOWS\system32\tasks\Microsoft\Windows\Custom er Experience Improvement Program\Consolidator[/ICODE]



        Download ClearLNK utility
        Unzip it to your desktop.
        Right click run as admin.
        Copy and paste the two lines below in red into the UI of the program, and then hit cure.

        [COLOR=rgb(184, 49, 47)]>>> “C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP Audio Switch.lnk” → [“C:\Program Files (x86)\HP\HPAudioSwitch\HPAudioSwitch.exe”]
        “C:\Users\Mark Wainman\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BitTorrent Web.lnk” → [“C:\Users\Mark Wainman\AppData\Roaming\BitTorrent Web\btweb.exe”]
        [/COLOR]
        [COLOR=rgb(184, 49, 47)]


        Run HijackThis! as admin! (located in the folder …Autologger\HijackThis)
        Do a system scan, then check each item below, [COLOR=rgb(184, 49, 47)]make sure and only check the items listed!![/COLOR][COLOR=rgb(184, 49, 47)]
        Then click Fix checked.
        The computer will need to reboot, allow it to do so.
        [/color]
        [COLOR=rgb(184, 49, 47)]
        [/color]
        [COLOR=rgb(184, 49, 47)]
        [/color]
        [COLOR=rgb(184, 49, 47)]
        O2 - HKLM..\BHO: (no name) - AutorunsDisabled - (no file)
        O2-32 - HKLM..\BHO: (no name) - AutorunsDisabled - (no file)
        O4 - HKLM..\SafeBoot: [AlternateShell] = (no file) (disabled)
        O9 - Button: HKLM..\AutorunsDisabled: (no name) - (no file)
        O9-32 - Button: HKLM..\AutorunsDisabled: (no name) - (no file)
        O15 - Trusted Zone: *.localhost
        O15 - Trusted Zone: https://rddunhamca-files.sharepoint.com
        O15 - Trusted Zone: https://rddunhamca-myfiles.sharepoint.com
        O15 - Trusted Zone: https://sequelsfashion-files.sharepoint.com
        O15 - Trusted Zone: https://sequelsfashion-myfiles.sharepoint.com
        O21 - HKLM..\ShellIconOverlayIdentifiers\AutorunsDisable d: (no name) - - (no file)
        O22 - Tasks: (disabled) Adobe Creative Cloud - "C:\Program Files\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe --showwindow=false --onOSstartup=true (file missing)
        O22 - Tasks_Migrated: \Microsoft\Windows\Mobile Broadband Accounts\MNO Metadata Parser - C:\WINDOWS\System32\MbaeParserTask.exe (file missing)
        O22 - Tasks_Migrated: Adobe Creative Cloud - "C:\Program Files\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe --showwindow=false --onOSstartup=true (file missing)
        O22 - Tasks_Migrated: HPAudioSwitch - C:\Program Files (x86)\HP\HPAudioSwitch\HPAudioSwitch.exe (file missing)



        Copy the content of the code box below.
        [COLOR=rgb(184, 49, 47)]Do not copy the word code!!!
        Right Click FRST and run as Administrator.
        Click Fix once (!) and wait. The program will create a log file (Fixlog.txt).
        Attach it to your next message.
        [COLOR=rgb(147, 101, 184)]Two Zipped folders will appear on your desktop, attach those as well.
        Code:
        Start::
        CloseProcesses:
        SystemRestore: On
        CreateRestorePoint:
        RemoveProxy:
        HKLM\SOFTWARE\Policies\Microsoft\Edge: Restriction <==== ATTENTION
        HKU\S-1-5-21-1586263983-1164605689-3317866451-1004\SOFTWARE\Policies\Microsoft\Edge: Restriction <==== ATTENTION
        S4 HP Comm Recover; "C:\Program Files\HPCommRecovery\HPCommRecovery.exe" [X]
        VirusTotal: C:\WINDOWS\system32\nlansp_c.dll
        File: C:\WINDOWS\system32\nlansp_c.dll
        Zip:C:\Program Files (x86)\LMIR0CCBA001.tmp_r.bat
        Zip:C:\Program Files (x86)\LMIR0CCBA001.tmp.bat
        C:\Users\Mark Wainman\Downloads\DriverEasy_Setup.exe
        C:\Users\Mark Wainman\AppData\Roaming\Easeware
        FirewallRules: [{F7535B92-5120-494A-9012-D4F48906263A}] => (Allow) C:\Users\Mark Wainman\AppData\Roaming\Zoom\bin\airhost.exe => No File
        FirewallRules: [{9204B6FD-E9D6-4C96-A37A-AB3AF3C10281}] => (Allow) C:\Users\Mark Wainman\AppData\Roaming\Zoom\bin\airhost.exe => NoFile
        sc stop sysmain
        sc config sysmain start= disabled
        sc stop DiagTrack
        sc config DiagTrack start= disabled
        sc stop dmwappushservice
        sc config dmwappushservice start= disabled
        sc stop lfsvc
        sc config lfsvc start= disabled
        cmd: netsh winsock reset catalog
        cmd: netsh int ip reset C:\resettcpip.txt
        cmd: net stop bits
        Move: C:\ProgramData\Microsoft\Network\Downloader\qmgr*.db C:\ProgramData\Microsoft\Network\Downloader\qmgr*.db.old
        cmd: net start bits
        cmd:  bitsadmin /list /allusers
        CMD: "%WINDIR%\SYSTEM32\lodctr.exe /R"
        CMD: "%WINDIR%\SysWOW64\lodctr.exe /R"
        CMD: "C:\Windows\SYSTEM32\lodctr.exe /R"
        CMD: "C:\Windows\SysWOW64\lodctr.exe /R"
        CMD: del /f /s /q %windir%\prefetch\*.*
        CMD: del /s /q C:\Windows\SoftwareDistribution\download\*.*
        CMD: del /s /q "%userprofile%\AppData\Local\Google\Chrome\User Data\Default\Cache\*.*"
        cmd: del /s /q "%userprofile%\AppData\Local\Microsoft\Edge\User Data\Default\Cache\*.*"
        cmd: del /s /q "%userprofile%\AppData\Local\Opera Software\Opera Stable\Cache\Cache_Data\*.*"
        CMD: del /s /q "%userprofile%\AppData\Local\temp\*.*"
        CMD: ipconfig /flushdns
        C:\Windows\Temp\*.*
        C:\WINDOWS\system32\*.tmp
        C:\WINDOWS\syswow64\*.tmp
        ExportKey: HKLM\SOFTWARE\Microsoft\Windows Defender\Exclusions
        emptytemp:
        Reboot:
        End::
        [/COLOR][/COLOR][/color][/color][/COLOR]

        Comment

        • Peccant
          PCHF Member
          • Dec 2022
          • 28

          #5
          completed. To avoid adding more variables to this fix, I’m going to leave my laptop at work for the evening and will continue with next steps when I return in the morning.

          Thank you

          Comment

          • Peccant
            PCHF Member
            • Dec 2022
            • 28

            #6
            I got as far as Kaspersky but cannot find the free virus removal download. Is one of their free trial packages what I should be downloading? I will complete the rest of the list in order once I hear back. Screenshots from the first steps are attached.

            Comment

            • Peccant
              PCHF Member
              • Dec 2022
              • 28

              #7
              Oh, and I’m looking into cooling pads. I do not currently use one.

              Comment

              • Malnutrition
                PCHF Moderator
                • Jul 2016
                • 7041

                #8
                Download a free virus removal tool — no installation required. Quickly scan for viruses and clean your device effortlessly from cyber threats.


                Kaspersky link. I’ll check everything else when I get home from work.

                Comment

                • Peccant
                  PCHF Member
                  • Dec 2022
                  • 28

                  #9
                  Thanks, keeps bringing me to the French Kaspersky page - I’ve clicked your link and typed it out manually but it keeps autodirecting.

                  Comment

                  • Malnutrition
                    PCHF Moderator
                    • Jul 2016
                    • 7041

                    #10
                    K. I’ll have to take care of that after work: It will be 7 o’clock tonight eastern time.

                    Comment

                    • Peccant
                      PCHF Member
                      • Dec 2022
                      • 28

                      #11
                      No problem, thanks. I’ll check it first thing in the morning. Should I move ahead with the other steps of your instructions or keep them in order once we have Kaspersky figured out?

                      Comment

                      • Malnutrition
                        PCHF Moderator
                        • Jul 2016
                        • 7041

                        #12
                        Finish whatever you can. And if you want, go to yandex.com and search for the kaspersky tool. May have Better luck.

                        Comment

                        • Malnutrition
                          PCHF Moderator
                          • Jul 2016
                          • 7041

                          #13
                          @Peccant Here it is Zipped and uploaded for you, Click here to download KVRT. Alternate link is here. Just need to unzip to your desktop.

                          Your computer seems to be handling the apps that are running just fine. System Idle process is running at 89 percent which means you could be running a lot more programs with ease on this machine.




                          Windows Key and R at the same time.
                          Type or Copy and paste [COLOR=rgb(184, 49, 47)]powercfg.cpl
                          Hit OK
                          Set your laptop to high performance.
                          Or Ultimate Performance if that option is available.



                          Let’s unpark all of the cores on your computer to see if we can free up some performance.

                          Press Windows Key + R to open the Run dialog box. Type in ‘Regedit’ in the text field and hit Enter
                          Then click Edit >>> Find.
                          Now type (copy and paste) the following code in the text field (without the quotes): “ [COLOR=rgb(184, 49, 47)]0cc5b647-c1df-4637-891a-dec35c318583 ” and click on ‘[COLOR=rgb(184, 49, 47)]Find Next’.
                          [ATTACH type=“full” alt=“1673379575824.png”]11304[/ATTACH]
                          A new window will open showing various registry items. All we need to look at are the ‘ValueMax’ and ‘ValueMin’ items.
                          Double-click on ValueMax and type the number [COLOR=rgb(184, 49, 47)] 0 [/COLOR][COLOR=rgb(184, 49, 47)]in the Value data field and press OK. Repeat the same for ValueMin.
                          Now reboot the computer and test the machine as normal.






                          Let me know how things turn out, after changing the Performance mode. and unparking the cores.[/color][/COLOR][/COLOR][/COLOR]

                          Comment

                          • Peccant
                            PCHF Member
                            • Dec 2022
                            • 28

                            #14
                            FRST64 won’t run the code you asked me to copy earlier. See error in Screenshot.
                            I downloaded KVRT, input the run command and the computer asked me what program to open “Mark” with. Could not move forward.
                            Power Config CPL doesn’t give me any options other than HP Recommended and Balanced. Maybe new to Windows 11? Alternatives? See screenshot.
                            RegEdit didn’t give me the expected results (no MinValue/MaxValue - see screenshot). I see LowRange and HighRange but I didn’t want to change if it wasn’t a different term for the same thing, expecially since the HighRange value is ffffff and not a numerical value.

                            I’m not having much luck with these latest instructions. I’m heading home for the evening but will be back in the morning to check on alternate paths forward. I really appreciate your time on this.

                            Thanks!

                            Comment

                            • Malnutrition
                              PCHF Moderator
                              • Jul 2016
                              • 7041

                              #15
                              For FRST make sure and copy from Start:: To End:: I forgot one colon at the end of End it was End: now it’s End:: So now it will work. My fault on that, sometimes it happens. lol
                              As far as the registry edit skip that. I do not have a windows 11 machine to test on, so we will not be messing with anything that I am not 100 percent certain about.
                              As far as Kaspersky [COLOR=rgb(147, 101, 184)]Make Certain KVRT is on the deskop!!, open elevated command prompt and copy and paste:
                              [COLOR=rgb(184, 49, 47)]C:\Users\Mark Wainman\Desktop\KVRT.exe -dontencrypt
                              [COLOR=rgb(184, 49, 47)] into it and hit enter.
                              [/COLOR][/COLOR]
                              [COLOR=rgb(184, 49, 47)][COLOR=rgb(184, 49, 47)]
                              If this does not work…just right click and run as admin do not worry about the -dontencrypt if there are any detections just screen shot them. Make sure and run it with the parameters I suggested.

                              [ul]
                              [li]Place check marks in the following categories:[/li][li]System memory[/li][li]Startup objects[/li][li]Boot sectors[/li][li]System drive[/li][/ul]


                              Download and run Quick CPU to unpark your Cores.

                              Quick CPU Tutorial…

                              [MEDIA=youtube]s49r4Eq2WkQ[/MEDIA]






                              Run this fix with FRST at the end of the day tomorrow. This will run a check disk on the machine, which may take several hours to complete.

                              [ICODE]Start:: CloseProcesses: SystemRestore: On CreateRestorePoint: StartBatch: ECHO Y|CHKDSK C: /F /R pushd c:\windows\system32 bcdedit.exe /set {default} recoveryenabled yes net stop bits net stop cryptSvc net stop wuauserv net stop msiserver del /s /q C:\Windows\SoftwareDistribution\download\*.* del /s /q "%userprofile%\AppData\Local\Google\Chrome\Use r Data\Default\Cache\*.*" del /s /q "%userprofile%\AppData\Local\Microsoft\Edge\Us er Data\Default\Cache\*.*" del /s /q "%userprofile%\AppData\Local\Opera Software\Opera Stable\Cache\Cache_Data\*.*" netsh winsock reset catalog netsh int ipv4 reset reset.log netsh int ipv6 reset reset.log ipconfig /release ipconfig /renew ipconfig /flushdns ipconfig /registerdns net start bfe net start bits net start cryptSvc net start eventsystem net start msiserver net start rpcss net start sdrsvc net start trustedinstaller net start vss net start winmgmt net start wuauserv bitsadmin /list /allusers bitsadmin /reset /allusers EndBatch: cmd: DISM.exe /Online /Cleanup-image /Restorehealth cmd: sfc /scannow cmd: winmgmt /salvagerepository cmd: winmgmt /verifyrepository cmd: "%WINDIR%\SYSTEM32\lodctr.exe" /R cmd: "%WINDIR%\SysWOW64\lodctr.exe" /R cmd: "%WINDIR%\SYSTEM32\lodctr.exe" /R cmd: "%WINDIR%\SysWOW64\lodctr.exe" /R EmptyTemp: Reboot: End::[/ICODE][/color][/color][/COLOR]

                              Comment

                              Working...