Solved Cleaning up my father's desktop

JamieM908

Thread Starter
Joined
Oct 18, 2003
Messages
18
Hi all. I am trying to help my Dad with his desktop, which is quite slow to boot up. He also notes various pop up windows that he frequently has to close. I have seen at least two of them:
"System Mechanic" popup saying New System Mechanic updates are available
"DriverUpdate" popup prompting about a new version

I would like to try and do a thorough cleanup of his desktop, but I have not done this type of thing for a while. Any help is appreciated!

Below is the system information.

Jamie

Tech Support Guy System Info Utility version 1.0.0.9
OS Version: Microsoft Windows 10 Home, 64 bit, Build 18362, Installed 20190801102723.000000-240
Processor: Intel(R) Pentium(R) CPU G2020T @ 2.50GHz, Intel64 Family 6 Model 58 Stepping 9, CPU Count: 2
Total Physical RAM: 4 GB
Graphics Card: Intel(R) HD Graphics
Hard Drives: C: 917 GB (840 GB Free);
Motherboard: Dell Inc. 0YXG0N, ver A00, s/n 9RC7PV1.CN7016334T01EW.
System: Dell Inc., ver DELL - 1072009, s/n 9RC7PV1
Antivirus: Windows Defender, Enabled and Updated
 

kevinf80

Kevin
Malware Specialist
Joined
Mar 21, 2006
Messages
11,440
Fass Post Preview
Hello JamieM908 and welcome to TSG....

Continue with the following:

If you do not have Malwarebytes installed do the following:

Download Malwarebytes from the following link:

https://www.malwarebytes.com/mwb-download/thankyou/

or,

https://downloads.malwarebytes.com/file/mb4_offline

Double click on the installer and follow the prompts. If necessary select the Blue Help tab for video instructions....

When the install completes or Malwarebytes is already installed do the following:

Open Malwarebytes, select > "settings" > "security tab"

Scroll down to "Scan Options" ensure Scan for Rootkits and Scan within Archives are both on....

Go back to "DashBoard" select the Blue "Scan Now" tab......

When the scan completes quarantine any found entries...

To get the log from Malwarebytes do the following:

  • Single click on the target sight above scanner window.
  • In the new window select Report
  • Double click on the Scan log which shows the Date and time of the scan just performed.
  • Click Export > From export you have two options:
    Copy to Clipboard - if seleted right click to your reply and select "Paste" log will be pasted to your reply
    Export toTxt - if selected you will have to name the file and save to a place of choice, recommend "Desktop" then attach to reply


  • Please use "Export to Txt" then attach the log to your reply...

Next,

Download AdwCleaner by Malwarebytes onto your Desktop.

Or from this Mirror

  • Right-click on AdwCleaner.exe and select
    user posted image
    Run as Administrator (for Windows Vista, 7, 8, 8.1 and 10 users)
  • Accept the EULA (I accept), then click on Scan
  • Let the scan complete. Once it's done, make sure that every item listed in the different tabs is checked and click on the Quarantine button. This will kill all the active processes
  • Once the cleaning process is complete, AdwCleaner will ask to restart your computer, do it
  • After the restart, a log will open when logging in. Please copy/paste the content of that log in your next reply

Next,

Download Farbar Recovery Scan Tool and save it to your desktop.

Alternative download option: http://www.techspot.com/downloads/6731-farbar-recovery-scan-tool.html

Note: You need to run the version compatible with your system (32 bit or 64 bit). If you are not sure which version applies to your system download both of them and try to run them. Only one of them will run on your system, that will be the right version.

If your security alerts to FRST either, accept the alert or turn your security off to allow FRST to run. It is not malicious or infected in any way...

Be aware FRST must be run from an account with Administrator status...

  • Double-click to run it. When the tool opens click Yes to disclaimer.(Windows 8/10 users will be prompted about Windows SmartScreen protection - click More information and Run.)
  • Make sure Addition.txt is checkmarked under "Optional scans"
    user posted image

  • Press Scan button to run the tool....
  • It will make a log (FRST.txt) in the same directory the tool is run. Please copy and paste it to your reply.
  • The tool will also make a log named (Addition.txt) Please attach that log to your reply.

Let me see those logs in your reply...

Thank you,

Kevin....
 

Cookiegal

Karen
Administrator
Malware Specialist Coordinator
Joined
Aug 27, 2003
Messages
117,899
Kevin, don't forget to mark the thread "In Progress". :)
 

Cookiegal

Karen
Administrator
Malware Specialist Coordinator
Joined
Aug 27, 2003
Messages
117,899
Jamie, my post was directed at Kevin and I'm not the one who requested the log but no matter, you did good by uploading them. I'm sure Kevin will get back to you as soon as possible.
 

kevinf80

Kevin
Malware Specialist
Joined
Mar 21, 2006
Messages
11,440
Thanks for those jamieM9068, and thanks for the prompt Cookiegal,

Continue:

Download Kaspersky Virus Removal Tool (KVRT) from here: https://www.kaspersky.com/downloads/thank-you/free-virus-removal-tool and save to your Desktop.

Select the Windows Key and R Key together, the "Run" box should open.



Drag and Drop KVRT.exe into the Run Box.



C:\Users\{your user name}\DESKTOP\KVRT.exe will now show in the run box.



add -dontcryptsupportinfo Note the space between KVRT.exe and -dontcryptsupportinfo

C:\Users\{your user name}\DESKTOP\KVRT.exe -dontcryptsupportinfo
should now show in the Run box.



That addendum to the run command is very important, when the scan does eventually complete the resultant report is normally encrypted, with the extra command it is saved as a readable file.

Reports are saved here C:\KVRT_data\Reports and look similar to this report_20200727_103821.klr Right click direct onto that report, select > open with > Notepad. Save that file and attach to your reply.


To start the scan select OK in the "Run" box.



The Windows Protected your PC window will open, select "More Info"



A new Window will open, select "Run anyway"



A EULA window will open, tick both confirmation boxes then select "Accept"



In the new window select "Change Parameters"



In the new window ensure all selection boxes are ticked, then select "OK" The scan should now start...



When complete if entries are found there will be options, if "Cure" is offered leave as is. For any other options change to "Delete" then select "Continue"



When complete, or if nothing was found select "Close"



Attach the report information as previously instructed....

Let me see those logsin your reply, also tell me if there are any remaining issues or concerns...

Thank you,

Kevin..
 

Attachments

Last edited:

JamieM908

Thread Starter
Joined
Oct 18, 2003
Messages
18
In my Friday 8:07 PM posting I included the logs called FRST.txt and Addition.txt which came from running the Farbar Recovery Scan Tool. Is that what you are referring to?
 

kevinf80

Kevin
Malware Specialist
Joined
Mar 21, 2006
Messages
11,440
Apologies JamieM908, I miss out the instructions for the fix. Continue:

Please download the attached fixlist.txt file and save it to the Desktop or location where you ran FRST from.

NOTE. It's important that both files, FRST or FRST64, and fixlist.txt are in the same location or the fix will not work.

NOTICE: This script was written specifically for this user, for use on this particular machine. Running this on another machine may cause damage to your operating system that cannot be undone.

Run FRST or FRST64 and press the Fix button just once and wait.
If the tool needs a restart please make sure you let the system restart normally and let the tool complete its run after restart.
The tool will make a log on the Desktop (Fixlog.txt) or wherever you ran FRST from. Please attach or post it to your next reply.

Note: If the tool warned you about an outdated version please download and run the updated version.

NOTE-1: As part of this fix all temporary files will be removed. If you have any open web pages that have not been bookmarked please make sure you bookmark them now as all open applications will be automatically closed. Also, make sure you know the passwords for all websites as cookies will also be removed.

The following directories are emptied:

  • Windows Temp
  • Users Temp folders
  • Edge, IE, FF, Chrome and Opera caches, HTML5 storages, Cookies and History
  • Recently opened files cache
  • Flash Player cache
  • Java cache
  • Steam HTML cache
  • Explorer thumbnail and icon cache
  • BITS transfer queue (qmgr*.dat files)
  • Recycle Bin

Important: items are permanently deleted. They are not moved to quarantine. If you have any questions or concerns please ask before running this fix.

The system will be rebooted after the fix has run.

Thank you,

Kevin
 

Attachments

JamieM908

Thread Starter
Joined
Oct 18, 2003
Messages
18
I have trouble knowing where the FRST exe file was downloaded to, and where it was saved. When I downloaded it, it just automatically opened the application. I do see a folder called C:\FRST\ which has subfolders called bin, Hives, Logs, and Quarantine. But I don't see the .exe, and I don't know how to run FRST again. Can you help me with this? Thanks!
 

kevinf80

Kevin
Malware Specialist
Joined
Mar 21, 2006
Messages
11,440
FRST was downloaded to and ran from this folder: C:\Users\Joe\Documents\Downloads
 

JamieM908

Thread Starter
Joined
Oct 18, 2003
Messages
18
Thanks for that. I ran FRST with the fixlist.txt file in that directory. Attached is the resulting Fixlog.txt
 

Attachments

kevinf80

Kevin
Malware Specialist
Joined
Mar 21, 2006
Messages
11,440
What is the current status of the PC, any remaining issues or concerns...?
 

JamieM908

Thread Starter
Joined
Oct 18, 2003
Messages
18
Everything seems good, thanks! My father reports that it boots up faster and he is not getting the pop-ups he used to have to constantly close.

I have a question about ongoing monitoring. Currently he has MalWareBytes installed. When I open it, the window says that he is on a Premium trial, which has 13 days left. I was not planning on Upgrading him to Premium. If I just let the 13 days pass without ungrading, will it just change to the Basic version on its own?

Let me know, and thanks so much for all your help!
 

Users Who Are Viewing This Thread (Users: 0, Guests: 1)

As Seen On
As Seen On...

Welcome to Tech Support Guy!

Are you looking for the solution to your computer problem? Join our site today to ask your question. This site is completely free -- paid for by advertisers and donations.

If you're not already familiar with forums, watch our Welcome Guide to get started.

Join over 807,865 other people just like you!

Latest posts

Staff online

Top