Several Programs Loading Slow [Solved/Closed]

Report
Posts
10
Registration date
Friday May 8, 2015
Status
Member
Last seen
October 6, 2017
-
Posts
48727
Registration date
Monday February 1, 2010
Status
Moderator
Last seen
September 19, 2020
-
Hello,

My Windows 8.1 Toshiba notebook has recently slowed down in terms of loading programs. The first time I load any program, it takes up to 3x longer than the following attempts, and tends to freeze very frequently. I face this issue with Chrome, Avast, and Windows Media Player the most (the latter when opening a file directly from the Windows Explorer).

The start-up itself takes a little longer than it did before, but it's not a major issue, just an annoyance. The programs, however, are beginning to cause problems as I use my notebook for events and such, and need some of them to load instantly (or at least without freezing).

-- Background --

I use Avast Free Antivirus 2015 and Malwarebytes Anti-Malware (Free) for security, none of which has found any issues in the latest full scans (done several times over the past month).

My disks are de-fragmented, except for a strange disk called "\\?\Volume{c[...]}\" (where [...] is a string of numbers and letters) which needs to be optimized, but refuses to follow any of the optimization commands.

I use most CCleaner functions on a regular basis, and have configured my start-up programs to the bare minimum for my needs.

11 replies

Posts
48727
Registration date
Monday February 1, 2010
Status
Moderator
Last seen
September 19, 2020
15,446
To help you and prescribe the remedy, I must make a diagnostic and to do so, I require a report.

1. Open this link and download ZHPDiag2 :

https://www.zebulon.fr/telechargements/securite/systeme/zhpdiag.html

(Don't be alarmed is the site is in French, it sometimes happens, the tool will take your system language and allow the download if you get a warning message, ignore it.)

2. Save the file on your Desktop.

3. Double click on ZHPDiag.exe and follow the installation instructions.

(For Vista and Win 7 users, click right to ensure you execute with admin right)

The tool creates three icons ZHPDiag, MRB, and ZHPFix (If necessary,we will use ZHPFix after log analysis).

4. Double click on the short cut ZHPDiag on your Destktop.

5. If you need to change the language, click on the little house, (bottom right) and change to English

6. Click on Full.

Wait for the tool to finished (maybe a long time)

7. Close ZHPDiag.

8. To transmit the report, click on this link :

https://authentification.site

9. Search the directory where you installed ZHPDiag (usually C:\desktop\zhpdiag.txt).
Ambucias
Moderator and Virus/Security Contributor
1
Thank you

A few words of thanks would be greatly appreciated. Add comment

CCM 2942 users have said thank you to us this month

Posts
48727
Registration date
Monday February 1, 2010
Status
Moderator
Last seen
September 19, 2020
15,446
Hello,

There are items that will certainly slowdown your machine.

Please download and run Adwcleaner:
https://ccm.net/download/download-24088-adwcleaner

You should also uninstall:
SystemK
Whitesmoke
DriverToolkit

There are 29 programmes or app that start at boot time. That is a lot of stuff using RAM.

Let me know and good luck
1
Thank you

A few words of thanks would be greatly appreciated. Add comment

CCM 2942 users have said thank you to us this month

Posts
10
Registration date
Friday May 8, 2015
Status
Member
Last seen
October 6, 2017
1
Hello,

Sorry for yet another late reply. I ran USBFix twice as I didn't have two HDDs with me the first time, but unfortunately I can't seem to access the first report any more. Here's the second one:

http://www.en.usbfix.net/report/?id=report/7.952/157f560bb8ff91c48ac7f2ea4c858a9bb4d32623.txt&nomfichier=157f560bb8ff91c48ac7f2ea4c858a9bb4d32623

I'm sorry for the haphazard attempt; it's been a crazy week. Hopefully my devices are cleaner than before. Thank you again for your help!
1
Thank you

A few words of thanks would be greatly appreciated. Add comment

CCM 2942 users have said thank you to us this month

Posts
10
Registration date
Friday May 8, 2015
Status
Member
Last seen
October 6, 2017
1
Dear Ambucias,

Thank you for your reply, and I'm very sorry for the delay.

Here is the link to the report: https://authentification.site/ts6T3/ZHPDiag.txt

I probably have a few malware in my system that I was not aware of, but you'll be able to decipher the report much better than I. Looking forward to your response!
Posts
10
Registration date
Friday May 8, 2015
Status
Member
Last seen
October 6, 2017
1
I ran adwcleaner and it got rid of some stuff for me, which has led to a slight improvement, although I have a feeling I will need to do a more thorough clean-up.

I disabled a few of the start-up programs; I hadn't even realized some of them were enabled till I dug deep!

And finally, I have yet to find/remove SystemK and Whitesmoke. I remember removing DriverToolkit, and adwcleaner also took care of the remaining bits, but the former two I'm having trouble locating.

Along with all of the above and a few minor tweaks to my notebook settings, life seems to be much easier at the moment.

Thank you for your help!
Posts
48727
Registration date
Monday February 1, 2010
Status
Moderator
Last seen
September 19, 2020
15,446
Hello,

From the report I analyzed, your RAM was down to 18% that will slow down a computer drastically

ZHP Diag created an icon called ZHP Fix.

Launch ZHP Fix and copy the following bold lines.

M2 - MFEP: RegExtension {9031880B-BFDF-F951-8186-F5B92464A61A} . (...) -- C:\Program Files (x86)\ver5SpeedCheck\184.xpi (.not file.) =>PUP.SpeedCheck
[HKCU\Software\AppDataLow\Software\SpeedCheck] =>PUP.SpeedCheck
[HKCU\Software\Reimage] =>Rogue.ReimageRepair
[HKCU\Software\UpdateStar] =>Adware.Boxore
[HKLM\Software\Reimage] =>Rogue.ReimageRepair
O43 - CFD: 16-03-2015 - 13:55:01 - [] ----D C:\Program Files (x86)\RelevantKnowledge =>Adware.RelevantKnowledge
O43 - CFD: 16-03-2015 - 12:11:07 - [] ----D C:\Program Files (x86)\SupTab =>PUP.SupTab
O43 - CFD: 16-03-2015 - 12:11:07 - [] ----D C:\Program Files (x86)\ver5SpeedCheck =>PUP.SpeedCheck
O43 - CFD: 13-01-2015 - 01:33:10 - [] ----D C:\ProgramData\WindowsMangerProtect =>PUP.Fuyu
O43 - CFD: 16-03-2015 - 12:11:07 - [0] ----D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RelevantKnowledge =>Adware.RelevantKnowledge
O43 - CFD: 11-03-2015 - 00:14:55 - [] ----D C:\Users\sony\AppData\Roaming\OpenCandy =>Adware.OpenCandy
HKLM\SOFTWARE\Microsoft\Tracing\StormWatch_RASAPI32 =>PUP.StormWatch
HKLM\SOFTWARE\Microsoft\Tracing\StormWatch_RASMANCS =>PUP.StormWatch
[HKCU\Software\Reimage] =>Rogue.ReimageRepair
[HKLM\Software\Reimage] =>Rogue.ReimageRepair
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\464AA55239C100F32AF2D438EDDC0F47] =>Adware.IMBooster
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\5652BA3D5FB98AE31B337BF0AF939856] =>Adware.IMBooster
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\86EB95E1AFCBABE3DB9ECCC669B99494] =>Adware.IMBooster
C:\Users\sony\AppData\Roaming\Mozilla\Firefox\Profiles\EP: RegExtension {9031880B-BFDF-F951-8186-F5B92464A61A} . (...) -- C:\extensions\Program Files (x86)\ver5SpeedCheck\184.xpi (.not file.) =>PUP.SpeedCheck^
C:\Program Files (x86)\RelevantKnowledge =>Adware.RelevantKnowledge^
C:\Program Files (x86)\SupTab =>PUP.SupTab^
C:\Program Files (x86)\ver5SpeedCheck =>PUP.SpeedCheck^
C:\ProgramData\WindowsMangerProtect =>PUP.Fuyu^
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RelevantKnowledge =>Adware.RelevantKnowledge^
C:\Users\sony\AppData\Roaming\OpenCandy =>Adware.OpenCandy^
[HKCU\Software\AppDataLow\Software\SpeedCheck] =>PUP.SpeedCheck^
[HKCU\Software\UpdateStar] =>Adware.Boxore^
C:\Windows\Reimage.ini =>Rogue.ReimageRepair


In ZHPFix, click on import, this will paste the above lines. Then click on GO.

You also have two antivirus. You should have only one. Not only do they consume ram but they may come in conflict giving false positives or miss out on detection. I suggest you disable one of them.

Let me know

Regards
Posts
10
Registration date
Friday May 8, 2015
Status
Member
Last seen
October 6, 2017
1
Hello,

I tried to follow the instructions for ZHPFix but for some reason, the script wasn't copied; I get a pop-up with a sample of what the script should be like. I even tried to copy the script manually, but it gives me the same pop-up.

I only have Avast enabled at the moment. I have to disable even that for a few minutes, or else it keeps deleting ZHPDiag.
Posts
48727
Registration date
Monday February 1, 2010
Status
Moderator
Last seen
September 19, 2020
15,446
Hi

You have Malwarebytes Anti-Malware version 2.1.6.1022

Please try this script
Script ZHPFix
FirewallRaz
EmptyPrefetch
EmptyTemp
EmptyFlash
M2 - MFEP: RegExtension {9031880B-BFDF-F951-8186-F5B92464A61A} . (...) -- C:\Program Files (x86)\ver5SpeedCheck\184.xpi (.not file.)
[HKCU\Software\AppDataLow\Software\SpeedCheck]
[HKCU\Software\Reimage]
[HKCU\Software\UpdateStar]
[HKLM\Software\Reimage]
C:\Program Files (x86)\RelevantKnowledge
C:\Program Files (x86)\SupTab
C:\Program Files (x86)\ver5SpeedCheck
C:\ProgramData\WindowsMangerProtect
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RelevantKnowledge
C:\Users\sony\AppData\Roaming\OpenCandy
HKLM\SOFTWARE\Microsoft\Tracing\StormWatch_RASAPI32
HKLM\SOFTWARE\Microsoft\Tracing\StormWatch_RASMANCS
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\464AA55239C100F32AF2D438EDDC0F47]
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\5652BA3D5FB98AE31B337BF0AF939856]
[HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\86EB95E1AFCBABE3DB9ECCC669B99494]
C:\Users\sony\AppData\Roaming\Mozilla\Firefox\Profiles\EP: RegExtension {9031880B-BFDF-F951-8186-F5B92464A61A} . (...) -- C:\extensions\Program Files (x86)\ver5SpeedCheck\184.xpi (.not file.)
C:\Windows\Reimage.ini


After, please upload a new ZHP Diag.

Regards
Posts
10
Registration date
Friday May 8, 2015
Status
Member
Last seen
October 6, 2017
1
It worked this time! Here is the new ZHPDiag report:

http://speedy.sh/VzGgW/ZHPDiag.txt

It seems I wasn't able to get rid of DriverToolkit properly. :(
Posts
48727
Registration date
Monday February 1, 2010
Status
Moderator
Last seen
September 19, 2020
15,446
Hi

Please delete:
C:\ProgramData\McAfee

You were not able to get rid of Driver Toolkit because it is an autorun virus which spreads to and through external memory devices.

Hello,
# Download USB Fix
  • It will launch automatically, and a shortcut will be created on your desktop.

  • Choose "Clean" option.
  • A pop-up will follow :
    Connect all your external data sources to your PC (Usb keys, external drives, etc...)
  • Once you're ready, click "OK".
  • While cleaning, you will loose access to your desktop, but this is normal.

The numbers of analysed and infected elements are displayed.

# Copy/paste the report here.

Tutorial : http://www.en.usbfix.net/2014/02/usbfix-tutorial-clean-option/

P.S. Most of the malware seem to have originated from UTorrent downloads.
Posts
48727
Registration date
Monday February 1, 2010
Status
Moderator
Last seen
September 19, 2020
15,446
Sorry but the second report does not show anything.

It was my pleasure to help you, you have been patient and cooperative.

Good luck