alwaysthinking Posted February 10, 2020 ID:1361767 Share Posted February 10, 2020 In addition, my computer's overall performance has slowed significantly as well. Opening web pages and applications takes much longer than it usually did. Something even as simple as right-clicking a file will take close to a minute to open the menu. My detection history shows some detections in the past few days, so I am suspecting that that may be the culprit, however my most recent threat scans have shown no threats detected or quarantined. I have attached my FRST.txt, Addition.txt, a screenshot of my threat scan checking for updates, a screenshot of my detection history, and the log of my most recent successful threat scan. Addition.txt FRST.txt log.txt Link to post Share on other sites More sharing options...
Root Admin AdvancedSetup Posted February 11, 2020 Root Admin ID:1361792 Share Posted February 11, 2020 Hello @alwaysthinking Go ahead and stop Malwarebytes and reboot the computer. Next, Please download and run the following Avast removal tool. You have left over elements from Avast on the system. http://files.avast.com/files/eng/aswclear.exe Then run the following fix. Please download the attached fixlist.txt file and save it to the Desktop.NOTE. It's important that both files, FRST or FRST64 and fixlist.txt are in the same location or the fix will not work. NOTICE: This script was written specifically for this user, for use on this particular machine. Running this on another machine may cause damage to your operating system. Run FRST or FRST64 and press the Fix button just once and wait. If the tool needs a restart please make sure you let the system restart normally and let the tool complete its run after restart. The tool will make a log on the Desktop (Fixlog.txt). Please attach or post it to your next reply. Note: If the tool warned you about an outdated version please download and run the updated version. fixlist.txt Thanks Link to post Share on other sites More sharing options...
alwaysthinking Posted February 11, 2020 Author ID:1361838 Share Posted February 11, 2020 I have completed the steps. My computer's performance went back to normal after I ran aswclear, and I was able to complete a threat scan in a normal amount of time. But I still ran FRST64 and produced the Fixlog anyway just in case. Also, I have noticed that Malwarebytes Tray Application keeps appearing in my Task Manager. Is this normal? Why does this keep appearing in Task Manager? Fixlog.txt Link to post Share on other sites More sharing options...
Root Admin AdvancedSetup Posted February 11, 2020 Root Admin ID:1361903 Share Posted February 11, 2020 Yes, it is normal for the Malwarebytes Tray to be in the list of Task Manager because it is running. Please go ahead and run reboot the computer one more time. Then run a new scan with FRST and attach both new logs so I can take a look. It looks like one item was not removed. Thanks Link to post Share on other sites More sharing options...
alwaysthinking Posted February 11, 2020 Author ID:1361963 Share Posted February 11, 2020 What exactly does the Malwarebytes Tray Application do? I have attached my FRST and Addition files from my new scan. Addition.txt FRST.txt Link to post Share on other sites More sharing options...
Root Admin AdvancedSetup Posted February 11, 2020 Root Admin ID:1361968 Share Posted February 11, 2020 That is part of our program that allows access to certain changes, it also allows alerts to users, etc. Do you read Chinese? There is a driver that appears to be in Chinese or some other obfuscated entry on the computer S3 ⸮僾否馹ﳞ嶌ቱ眖㚩츮訑ꭉ㼃䗦莻₁皑屛ﵙ嗱頾艬℆㻔䑡识㝾쾩翖㡁썮崦發뎉쫄훮ᵙ濖ꇡᓳꡋ腹쬓흩瞫눎승岡縁㧆ꦜ胾ᔤꀶଶ湑暆꜖�쉱漬Ⳟ펔䦹Љ뢱闦ඣ等넛Ḯ퉃䠾滻ⵙ�쏶村ꚑ냌ᾩ竎륦鑡מ煛c䀇⦔劭扯湩⸥f⸥㜱gHdsKe; C:\Windows\system32\drivers\⸮僾否馹ﳞ嶌ቱ眖㚩츮訑ꭉ㼃䗦莻₁皑屛ﵙ嗱頾艬℆㻔䑡识㝾쾩翖㡁썮崦發뎉쫄훮ᵙ濖ꇡᓳꡋ腹쬓흩瞫눎승岡縁㧆ꦜ胾ᔤꀶଶ湑暆꜖�쉱漬Ⳟ펔䦹Љ뢱闦ඣ等넛Ḯ퉃䠾滻ⵙ�쏶村ꚑ냌ᾩ竎륦鑡מ煛c䀇⦔劭扯湩⸥f⸥㜱gHdsKe.sys [105136 2017-09-08] (AVAST Software) [File not signed] A Google Translation only seems to translate some of it. Link to post Share on other sites More sharing options...
Root Admin AdvancedSetup Posted February 11, 2020 Root Admin ID:1361969 Share Posted February 11, 2020 Did you download and run the Avast Cleaner I linked to above? Link to post Share on other sites More sharing options...
Root Admin AdvancedSetup Posted February 11, 2020 Root Admin ID:1361970 Share Posted February 11, 2020 Let me have you run the following to see if it will show more of what is going on there. Please download the attached fixlist.txt file and save it to the Desktop.NOTE. It's important that both files, FRST or FRST64 and fixlist.txt are in the same location or the fix will not work. NOTICE: This script was written specifically for this user, for use on this particular machine. Running this on another machine may cause damage to your operating system. Run FRST or FRST64 and press the Fix button just once and wait. If the tool needs a restart please make sure you let the system restart normally and let the tool complete its run after restart. The tool will make a log on the Desktop (Fixlog.txt). Please attach or post it to your next reply. Note: If the tool warned you about an outdated version please download and run the updated version. fixlist.txt Thanks Link to post Share on other sites More sharing options...
alwaysthinking Posted February 12, 2020 Author ID:1361999 Share Posted February 12, 2020 Yes, I used the Avast Cleaner to delete my "avast!" folder from my C drive. No, I don't read Chinese. There are also some Korean and Hebrew characters in there. I don't know why the file was named like this. I have located the file in my C drive and its properties say that it's from AVAST Software. Should I run the Avast Cleaner again to delete this file? Link to post Share on other sites More sharing options...
Root Admin AdvancedSetup Posted February 12, 2020 Root Admin ID:1362091 Share Posted February 12, 2020 Yes, please go ahead and delete that file. We'll also probably need to scan your Registry another way to try to remove that value Try opening REGEDIT on your system and then browse to the following key location: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services See if you can find an entry with Unicode like that and let me know. Link to post Share on other sites More sharing options...
alwaysthinking Posted February 13, 2020 Author ID:1362198 Share Posted February 13, 2020 I deleted the file from the C drive with the Avast Cleaner, but afterwards I still found a similarly named entry in the REGEDIT. Link to post Share on other sites More sharing options...
Root Admin AdvancedSetup Posted February 13, 2020 Root Admin ID:1362226 Share Posted February 13, 2020 Do you know how to remove the entry in the Registry? If so and you know you're removing only the correct bad value, or key then go ahead and remove. If it is a Parent - Top key location then do not delete it. Show me a screen shot first please. Thanks Link to post Share on other sites More sharing options...
alwaysthinking Posted February 13, 2020 Author ID:1362290 Share Posted February 13, 2020 Here is a screen shot of the registry. I can right click the entry and see a delete option, but I don't know how to identify if it's a Parent - Top key location. Link to post Share on other sites More sharing options...
Root Admin AdvancedSetup Posted February 13, 2020 Root Admin ID:1362314 Share Posted February 13, 2020 No it's not a Parent. The Parent in the tree is SERVICES - do not delete that one. Go ahead and delete the one you've found and selected. That is the correct option. Let me know if it won't delete Link to post Share on other sites More sharing options...
alwaysthinking Posted February 14, 2020 Author ID:1362398 Share Posted February 14, 2020 I successfully deleted it. Link to post Share on other sites More sharing options...
Root Admin AdvancedSetup Posted February 14, 2020 Root Admin ID:1362470 Share Posted February 14, 2020 Great. Glad you were able to remove it without issue. Let me have you do a clean removal and reinstall of Malwarebytes now https://support.malwarebytes.com/hc/en-us/articles/360038522234-Uninstall-and-reinstall-Malwarebytes-for-Windows-with-the-Malwarebytes-Support-Tool Take your time and be patient. Let me know if there are any issues with that Link to post Share on other sites More sharing options...
alwaysthinking Posted February 15, 2020 Author ID:1362633 Share Posted February 15, 2020 I completed the instructions in the link you provided. Link to post Share on other sites More sharing options...
alwaysthinking Posted February 15, 2020 Author ID:1362634 Share Posted February 15, 2020 Is "FRSTEnglish.exe" supposed to download into my computer along with the Malwarebytes Support Tool? Link to post Share on other sites More sharing options...
Root Admin AdvancedSetup Posted February 16, 2020 Root Admin ID:1362772 Share Posted February 16, 2020 Yes, that is a download from our MBST program that is used to help gather logs when needed. In your case we're just using MBST to do the removal and reinstall of our program. Please do that and let me know how it goes Link to post Share on other sites More sharing options...
alwaysthinking Posted February 17, 2020 Author ID:1362856 Share Posted February 17, 2020 I used the MBST and it seemed to have gone fine. In recent days, I have noticed my computer's internet has occasionally stopped working until I restart the computer, but I'm not sure if that's a virus/malware issue. Link to post Share on other sites More sharing options...
Root Admin AdvancedSetup Posted February 17, 2020 Root Admin ID:1362858 Share Posted February 17, 2020 Are you using Wireless or Wired connection to your router? Can you please take a screen shot and show me which version of Malwarebytes you're using. Here is mine Link to post Share on other sites More sharing options...
alwaysthinking Posted February 18, 2020 Author ID:1363115 Share Posted February 18, 2020 I am using wireless. Strangely, the last post that I made (post #20) was made successfully while my internet was not working on the rest of my computer. For some reason, the internet worked correctly on the tab that had this website open and another tab that had Instagram open, but the internet stopped working in all of my other tabs when I tried to visit a new website. The only reason I can think of is that the tabs that worked were already open when the internet stopped working, but that doesn't explain why the internet still worked on those tabs. Here is my version of Malwarebytes. The "update package version" when I first opened the program was 1.0.19426. I closed the program and opened it a few minutes later and it was 1.0.19428. Then I clicked "check for updates" and it became 1.0.19430. I have it set to check for updates and install them automatically, but this behavior still occurred. Link to post Share on other sites More sharing options...
Root Admin AdvancedSetup Posted February 18, 2020 Root Admin ID:1363123 Share Posted February 18, 2020 Please close all your browsers. Then restart your computer and let me know if you're still having any connections issues or not Link to post Share on other sites More sharing options...
Root Admin AdvancedSetup Posted February 23, 2020 Root Admin ID:1363880 Share Posted February 23, 2020 Hello @alwaysthinking Following up to see how things are going. Please post a status update. Thanks Link to post Share on other sites More sharing options...
alwaysthinking Posted February 23, 2020 Author ID:1363918 Share Posted February 23, 2020 In the past few days, I have shut down and turned back on my computer multiple times, and I have not experienced any connection issues as of yet. Link to post Share on other sites More sharing options...
Recommended Posts