Computer slowed to a crawl - hidden virus or time for a new PC?

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by ElViajador, Aug 19, 2011.

  1. ElViajador

    ElViajador Private E-2

    I followed the >read this first< and will post the relevant logs.

    My problem is my PC is running ridiculously slow, opening photoshop seems to bump the CPU usage to 100%. Also, Chrome won't run. Not too fussed about chrome... but worried what this is a symptom of. Using explorer at the moment.

    Before running all the Fix programs my CPU and physical memory were stuck at just under 100% so they've helped somewhat, but I'm still running at a solid 50% on both with nothing but internet explorer.

    Checked my processes as I wrote this and noticed that killing Adobe Update manager, DivX, and Dropbox brought me down to about 0% CPU and knocked the physical down about 0.8 gigs.

    Is it normal for these programs alone to be so resource intensive? And what's with Chrome? Am I just completely ignorant and unaware that I just need a new computer? I figured 2.5 GHz and 4Gig ram would be enough to run photoshop and a web browser at the same time without needing to take up knitting to kill wait times. I'm hoping this is something I can fix rather than replace.

    Thanks!
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Your logs are all clean so it is not looking like you are having malware problems and you may need to work your issues in the Software Forum. However let's first dig a little deeper to be sure nothing else could be hiding from view by running the below two scans.

    Goto the below link and follow the instructions for running TDSSKiller from Kaspersky
    • Be sure to attach your log from TDSSKiller
    Now also lease also download MBRCheck to your desktop.

    See the download links under this icon [​IMG]
    • Double click MBRCheck.exe to run (vista and Win 7 right click and select Run as Administrator)
    • It will show a Black screen with some information that will contain either the below line if no problem is found:
      • Done! Press ENTER to exit...
    • Or you will see more information like below if a problem is found:
      • Found non-standard or infected MBR.
      • Enter 'Y' and hit ENTER for more options, or 'N' to exit:
    • Either way, just choose to exit the program at this point since we want to see only the scan results to begin with.
    • MBRCheck will create a log named similar to MBRCheck_07.16.10_00.32.33.txt which is random based on date and time.
    • Attach this log to your next message. (See: HOW TO: Attach Items To Your Post )
     
  3. ElViajador

    ElViajador Private E-2

    Thanks a million for getting back to me so soon!

    I attached the logs from the programs below. The computer still doesn't seem to have any top end, as soon as I start running multiple programs (explorer +photoshop +music) it's struggling to keep up; this is definitely not normal operation.

    Anyways hopefully these tell you something!
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It still may not be malware. The only questionable item is the unknown MBR on the second hard disk in your system ( the 100 GB Fujitsu drive ) which I assume has another OS on it? You could either temporarily remove this drive to see if it helps, or you could attempt rewriting the MBR on it to a standard MBR to see if it changes anything. It may be a safer test to just try unplugging this drive. Then boot back up and rerun MBRcheck and attach a new log. Also test to see how things work with this drive removed.


    Other possible issues are left overs from AVG, uTorrent and some other non malware stuff running (like Google junk ).

    I also recommend immediately uninstalling Conduit Engine
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    By the way, your first logs show the below

    Code:
    Image Name                     PID Session Name        Session#    Mem Usage
    ========================= ======== ================ =========== ============
    wmpnetwk.exe                  2812 Services                   0  2,335,868 K
    This should not be using so much memory. This is not malware, but it is not correct. Are you really using this? See this?? http://www.addictivetips.com/windows-tips/fix-wmpnetwk-exe-in-windows-7/
     
  6. ElViajador

    ElViajador Private E-2

    Here's the log. Weirdly enough, killing WMPNETWK seems to have brought Chrome back to life.

    Computer is still running oddly slow though... anything in the log?
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    wmpnetwk.exe - runs as a service and will automatically restart within a short time frame. Thus the benefit of killing it is short lived. You need to disable it or uninstall Windows Media Player. You could also look into permanently disabling the service.

    Since this is not a malware problem. I suggest that you post in the Software Forum for help. This problem has been around for along time ( re: http://forums.majorgeeks.com/showthread.php?t=112742 )



    Since you are not having malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista or Win 7, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds