Periodic unresponsiveness in Win 7

Discussion in 'Software' started by FieroGT42, Jan 17, 2011.

  1. FieroGT42

    FieroGT42 Private E-2

    I'm getting strange, periodic lags every several minutes. Nothing unusual shows up in HJT. I'm not familiar with Win 7 services as I am with XP, but it looks okay to me. The only odd thing I've seen is Ask toolbar which I accidentally allowed to install with some application. I removed it. Problem still persists. I haven't installed anything recently except Vidalia bundle straight from it's home page, and I haven't used it yet.

    This is a decently fast laptop with plenty of ram and CPU cycles to spare, everything will slow down to the point that only 1 letter per second while typing, or sometimes it seems to completely hang. Everything hangs: keyboard, mouse, touchpad, animated images. CPU usage never registers high though, and the RAM and page file usage is not a problem. This happens on AC power or battery, regardless of what power profile I"m using (custom or defaults).

    Sometimes when it hangs I see another task show up on the taskbar, but it disappears as soon as it starts, before it even shows a name. This seems to happen a fraction of a second before it stops hanging and seems VERY suspicious to me.

    HW (not suspected): Gateway T-1625 w/ AMD Turion X2 TL-60, 2GB ram.
    SW is Win 7 (legit), with Firefox, PeerBlock, uTorrent, Vidalia bundle (not being used), Comodo internet security. Everything is fully up to date.

    I have some other computers to fix tomorrow, but if I have time I'll see what registry, HDD, and network monitors come up with. Something funny must be going on.

    What else should I scan with besides HJT? This is an important computer to get cleaned up. Thanks!
     
  2. satrow

    satrow Major Geek Extraordinaire

    Checkout what the Disk Activity is like using the Resource Monitor, it's accessible via a button on the bottom of TaskMan's Performance tab.

    If you really think there's something suspicious going on, your next steps should be in the direction of the Malware forum to study then enact the Read and Run me.

    Even if your subsequent logs come up clean, those logs can often help to pinpoint the culprit if you need to revisit this thread to ask for further help with this issue.
     
  3. FieroGT42

    FieroGT42 Private E-2

    Any further help would be appreciated. It seems to be lagging much worse when I'm typing, and it's interfering with my college essays.

    Disk activity doesn't look abnormal, even when it hangs. HDD LED doesn't do anything funny either.

    Edit: One slight correction: When it hangs, animations stop and everything is completely unresponsive EXCEPT for the touchpad moving the cursor. I can't click or type during the hangs, but the key presses and clicks do register when it stops hanging.

    msconfig, etc. looks okay
    HJT looks okay
    Sophos: error starting
    RootRepeal: no Windows 7 versions?
    Comodo: clean
    MBAM: clean
    ComboFix: clean
    ProcessMonitor: nothing looks unusual, no help in tracing this program that starts/exits so quickly.

    I skimmed the logs and didn't see anything obviously wrong. I manually quarantined these two files until I can find something about them:

    c:\windows\zip.exe (combofix leftover?)
    system32\gadmsysw.dll (mentioned here: http://forums.majorgeeks.com/showthread.php?t=118913 and also in some ComboFix scans under "find3m")

    And finally, there are a few things in the logs with very, very long entries that I'm not used to, like the following:

    WUDFHost.exe "C:\Windows\system32\WUDFHost.exe" -HostGUID:{193a1820-d9ac-4997-8c55-be817523f6aa} -IoEventPortName:HostProcess-35d533e1-6db4-4188-bd62-eb9d7dbcb79d -SystemEventPortName:HostProcess-1e93ff71-57a3-4cab-b4fb-af4e979b2a88 -IoCancelEventPortName:HostProcess-3ee23a24-29ee-4d5a-84a9-5b9ce26c6618 -NonStateChangingEventPortName:HostProcess-b205a125-a140-4ffc-af8e-c50e89aaca5d -ServiceSID:S-1-5-80-2652678385-582572993-1835434367-1344795993-749280709 -LifetimeId:31c66397-e2af-4cc3-b882-ffcdd7e06fe6 2392
     

    Attached Files:

  4. satrow

    satrow Major Geek Extraordinaire

    I see 3 potential triggers for malware in the logs, I didn't/can't look for malware itself as I'm not trained to do so.

    Combined with your noticing 2 files which you've already quarantined and the process that starts/stops before you can read the name, I'd strongly advise that you create a new thread over in the Malware section of the forum, post your logs and all error messages, link them to this thread.

    Once we're sure that you're clean, we may be able to narrow this down some more.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds