Malware issues?

Status
Not open for further replies.
I'd still like your help removing the Toshiba stuff. I will research the startup repair thread and get back to you.

thank you for your patience
 
Sorry for the delay in replying, I didn't get a notice you had replied.

The items I saw in your add/remove programs list were not involved in startups.

Whats the age of this computer?

I may have asked this already, if you boot into safe mode does it run still very slow?
 
Hi Juliet

I can't recall but probably about 3-5 years max. Probably closer to 3 years.

I haven't booted into safe mode. I'm not sure how to do that. I'm a little nervous with the advance level stuff.

I read the links you gave me about running startup repair and I was not following the material/steps as they present it such that I was uncomfortable attempting this myself. The steps don't look the same and the commands are not what I am seeing or maybe it is in a different order, but it doesn't look familiar enough. It's not like how you guys explain stuff which is very clear and precise.

My computer took about 15-20 mins to boot up tonight. It is so slow. I did a hard shutdown on it today after IE was so slow to run I got sick of it and just shut it off.

Opening the file folder, excel or photos can take anywhere from 1-3 minutes to open. It's crazy. It takes FOREVER for IE to open. Maybe it's corrupted?

I can never tell if Windows defender turns back on when Kaspersky is on, or if there are programs running in the background. I wish there was a way to stop all programs from running automatically or at least be able to open a window to see what is running at any given moment and have the option to shut it off.

I think I shut off the idrive or icloud thing which was always updating.
 
from the symptoms, it could be either a hard drive issue or a ram issue
the system was trying to do automatic update to a backup, how updated is your W10? Do you have all of the most recent updates? If your system is playing catch up to install those patches, it will take a while.

Windows Defender will not run as long as you have Kaspersky on the machine. By design it will/should be disabled because of having the 2 antivirus on there.

We havent run a rootkit scan, not saying you have one but this should tell us if any of these problems are related to infection.

Malwarebytes Anti-Rootkit

Download Malwarebytes Anti-Rootkit Beta and save it to your desktop.
  • Double-click the file to run it. Select the extraction path as your desktop. (MBAR will be launched shortly after the extraction)
    HTCF1SV.png
  • Click on Next, and then on the Update button to let it update its database. Once the database has been successfully updated, click on Next
  • Make sure all the checkboxes are checked, then click on the Scan button, and let it complete the scan (this can take a while)
  • Once the scan is done, make sure that every item is checked, and click on the Cleanup button (a reboot might be required)
  • After that (and the reboot, if one was required), go back in the mbar folder and look for a text file called mbar-log-TODAY'S-DATE.txt
  • Copy/paste the content of that log in your next reply.
---------------------------------------------
 
Thanks for your help on this Juliet *just a heads up, I may be a bit slow to respond/address this given heading into xmas week and working late, family obligations, etc so I haven't had much time in the evenings, but I will stay on it*

Pretty sure that windows runs updates regularly, but I did notice that when I went into the system folder and looked under updates, it said there were several updates that have failed to install and it will keep trying. I tried to manually run the update but it seems to be having trouble going through.

As far as Windows defender is concerned, I constantly get conflicting messages. Sometimes after I reboot is says I need to turn on my security settings for Kaspersky, sometimes it says I need to turn on Windows, sometimes it says both are off and sometimes it appears both are on......it's really confusing. Defender is the tricky one because I can't really tell if it is on or off. MS is sneaky that way I guess.

I will try running rootkit scan tonight or tomorrow and get back to you with results.

thank you!
 
Thanks for your help on this Juliet *just a heads up, I may be a bit slow to respond/address this given heading into xmas week and working late, family obligations, etc so I haven't had much time in the evenings, but I will stay on it*

Pretty sure that windows runs updates regularly, but I did notice that when I went into the system folder and looked under updates, it said there were several updates that have failed to install and it will keep trying. I tried to manually run the update but it seems to be having trouble going through.

As far as Windows defender is concerned, I constantly get conflicting messages. Sometimes after I reboot is says I need to turn on my security settings for Kaspersky, sometimes it says I need to turn on Windows, sometimes it says both are off and sometimes it appears both are on......it's really confusing. Defender is the tricky one because I can't really tell if it is on or off. MS is sneaky that way I guess.

I will try running rootkit scan tonight or tomorrow and get back to you with results.

thank you!
I understand this is a bad time to try and work on the computer. It's very close to the holidays and family comes first.

You might have hit the nail on the head here. I don't think this is related to malware, there seems to be a battle between Microsoft in a loop to install failed updates (No idea why) and possibly an overpowering antivirus.
When Windows updates are trying to install it's at bootup (This creates an abnormal long time trying to install the updates). And since it fails it starts the cycle again trying to download which uses a large amount of resources.....creating lag.

Found an article that might give some insight.

https://support.microsoft.com/en-in/help/10164/fix-windows-update-errors


Run Windows Update Troubleshooter.
Manually download and install updates.
Disable your antivirus.
 
Juliet

I rant the rootkit scan and there was no log. It said no malware was found the computer is clean.

I will review your other posts but maybe I need to work instead on hardware/software issues?

Chris
 
Juliet

I ran the rootkit scan and there was no log. It said no malware was found the computer is clean.
No log was created because there was nothing to remove.

I will review your other posts but maybe I need to work instead on hardware/software issues?
Chris

Thats my thoughts.
 
Hi Juliet

I hope you had a nice holiday season.

So I downloaded the program from Microsoft that was supposed to address my update issues. I ran it and it just seemed to get caught in a loop where it just never completed its process for repairing my MS downloads. When I check my updates files, it says there was an error running updates but the update never gets completed. It keeps trying to re-run it, I suppose, but it never gets updated.

Not sure what to try at this point.

thanks

Chris
 
I saw something recently that a Microsoft update went out thats kinda created havoc, don't know if this relates to you and the problems your having but do keep this under your hat.

Before completely running out of ideas of what to do next:

Kaspersky Internet Security

CodeIntegrity:
============
There are several errors related to Kaspersky
Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MpCmdRun.exe) attempted to load \Device\HarddiskVolume4\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 20.0\x64\antimalware_provider.dll that did not meet the Microsoft signing level requirements.

This doesn't mean of course the entire problems/s is all because of Kaspersky but it is a possibilty.

What you can try
Uninstall Kaspersky Internet Security, then re-install it again to see if the issues remain.
Do have handy any paid subscription info if this is a paid for subscription.

Download and run their uninstaller tool from this site.
This will remove all traces of the program that was uninstalled.
https://support.kaspersky.com/1464

Restart the computer when the removal is completed.

If all is well and if you wish reinstall the program.
Restart thie computer after the installation.
I can also supply a list of free antivirus and paid for antivirus applications if needed.
-----

Lets try this:
Download Windows Repair (All-in-One) Portable


Disable all your antivirus and antimalware software - see how to do that from here <= Important

- Right click on
QfBzvq1.png
and select Run as Administrator (XP users just double click) to start Windows Repair All-In-One.
(Windows Vista/7/8 users: Accept UAC warning if it is enabled.)

- A window will appear. Click Step 2.
2f8o60N.png


- Click the Open Pre-Scan button, then click Start Scan. Wait for Windows Repair to finish scanning.

- Depending on which error Windows Repair found, click Repair, Repair Reparse Point or Repair Environment Variable accordingly. When the button changes to "Done!", click the close button to return to Windows Repair.

- Go to Step 3, then click Check in the See If Check Disk Is Needed.
Ymy7crZ.png


- If Windows Repair stated that errors are found, click Open Check Disk At Next Boot. Choose (/R) Fixes errors on the disk also locate bad sectors and recovers readable information, then click Add To Next Boot. Reboot the computer to let Windows check the disk.

- Go to Step 4, then click Do It.
zDtdN75.png


- Go to Step 5. Under System Restore click Create.
f7lEe1N.png


- Go to Repairs and click Open Repairs. Unselect all checkmarks, except Repair WMI, then click Start Repairs.
PGv2vtD.png


- By default Windows Repair All-In-One will create a "Logs" folder in its folder on the Desktop. Please post the contents of the log in your next reply.

Let me know how you make out on the above.
 
Thanks Juliet. This will take me some time.

Is there a reason the MS issue is hush hush?

And are you saying YOU see an issue with Kaspersky on my machine or is it something you've read? Maybe I can contact Kaspersky and see if they know about any issues?
 
Thanks Juliet. This will take me some time.

Is there a reason the MS issue is hush hush?

And are you saying YOU see an issue with Kaspersky on my machine or is it something you've read? Maybe I can contact Kaspersky and see if they know about any issues?

The Microsoft issues are not hush hush. Every month there are new reports on google and other web sites reporting problems with the latest ones distributed.

The FRST tool reports issues found in the event viewer, there is where I saw errors referring to Ksapersky
CodeIntegrity:
============
There are several errors related to Kaspersky
Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MpCmdRun.exe) attempted to load \Device\HarddiskVolume4\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 20.0\x64\antimalware_provider.dll that did not meet the Microsoft signing level requirements.

This doesn't mean of course the entire problems/s is all because of Kaspersky but it is a possibility.
You would probably help yourself out contacting Kaspersky with what is found in the report. There wasn't just one there were several.
 
Glad we could help.
SakDYGv.gif

Since this issue appears resolved ... this Topic is closed.
 
Status
Not open for further replies.
Back
Top