PC running very slow of late, CPU usage upto 100%

Discussion in 'Malware Help (A Specialist Will Reply)' started by monalisa, Dec 8, 2007.

  1. monalisa

    monalisa Private E-2

    Hello,

    Of late ( no new software installed during this period), my laptop is running very slow and the Task manager shows CPU usage cycles between 0 all the way to 100%.
    The Task Manager Process List shows several entries for svchost.exe

    I have completed the basic steps specified in "Read & Run me first" except the AVG Antispyware scan as I already had "Ad-Aware SE Personal" installed and it showed no threats.

    Could anyone please take a look at the MGlog files attached herewith and suggest ways to speed up the performance?

    Thanks.

    Monalisa
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    As noted in the READ ME, slow PCs are not always related to malware.

    What process or processes are using 100% of your CPU.

    The steps in the READ ME are not optional. Also note Ad-Aware SE is not even close to being as good as AVG Antispyware. Please run AVG Antispyware and attach the requsted log.

    Also you need to attach the requested log from ComboFix.
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I don't expect that ComboFix or AVG AntiSpyware are going to show us any major issues. You don't appear to be having malware problems. However here are a few things you should do and I have a possible tip at the end the could be part of your problem.

    Uninstall the below old Sun Java version
    J2SE Runtime Environment 5.0 Update 9

    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"

    After clicking Fix, exit HJT.


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger.

    Make sure you tell me how things are working now!

    TIP:I see C:\WINDOWS\system32\msiexec.exe which is Microsoft installer. This should not normally be running. Often when this is seen running, it could mean that you have an incomplete installation or uninstall of some software. You should try running the below to see if it finds anything:

    Windows Installer CleanUp Utility
     
  4. monalisa

    monalisa Private E-2

    Hello,

    Few Points:
    Before receiving this reply, I thought I would do AVG Antispyware scan as well, and actually I did it twice - the first time I had some start-up processes stopped from msconfig, and the scan took ~ 40 mins, the second time I used 'Normal Start Up Mode" and it took 3hr 30 min and it did NOT find a single thing.

    I re-did the Combo-Fix, Spybot SD & MGTools in "Normal Start-up too. (All Logs attached). Since SPybot didnt find anything, I have actually deleted it after the scan as it looked to me it was slowing down the system.
    (Combo Fix installs a IE shortcut on my desktop eack time it scans - why??)

    During each of the scans, the CPU usage was shown to be 100%. Essentially running of a single process brings the usage upto 100%.

    Having gone thru' Read-Me, I uninstalled MS Java and installed latest java - so thats one new installation I did.

    I did the steps specified in your reply. And I have attached the 2nd MGZip file after using analyze.exe to fix the 2 entries. I do get an error each time I run MGtools. Screenshot attached.
    Its still slower than what it was about a couple of weeks ago - when I was on travel and had to access internet from a conference center. Things changed after that - though cannot detect any spyware etc.

    The cleanup is showing a bunch of files, will attach in the next post.

    Further suggestions?
     

    Attached Files:

  5. monalisa

    monalisa Private E-2

    Remaining Log files.
     

    Attached Files:

  6. monalisa

    monalisa Private E-2

    Windows Installation CLeanup Utility - Listings attached. Dont know what to do this list - too many files listed.!
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you installed Spybot as requested in the READ ME without Teatimer, Spybot will not slow your PC down because it is never running unless you do a scan.

    Not sure why this is happening as I never saw this. Do you normally not have an IE shortcut on your Desktop?

    This is occurring because you never installed the Microsoft .NET Framework package from Microsoft update. This too bad too since it could have shown us additional information. You could have something hooking into your running process and the processDLL.exe log would show us this.

    The only log that is showing a possible issue is ComboFix which showed the below
    This is what I was referring to about processDLL.exe possibly showing something hooked into running processes. This could mean you do have a problem like this.


    Please run this: Running GMER to detect rootkits and attach the GMER log



    Don't do anything with this. I don't see anything wrong.
     
  8. monalisa

    monalisa Private E-2

    Attached is the gmer log.

    My laptop still runs as slow as it was.

    Could stopping some of the start up processes like ( DVD launcher/ Nikonview etc) help? And If I have to do that without going on to msconfig and do "selective start up" after killing some of the processes there, is there a better way to do it?

    Looking at my HJT or other logs, could you please suggest what other processes could be stopped without hampering normal operation?
    Its like, whenever I am running any processes for example, firefox, that single process use up ~ 100% CPU.
    Any suggestions?

    And to answer your qs, I do NOT have IE shortcut on desktop as I use mozilla firefox usually, and if I have to use IE I pull it up from the start\program files list.

    Please help me improve the recently slowed down PC performance. Could it be a problem of the RAM itself? Like its dying or something? If its a hardware problem how do I now?

    Thanks.
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It's clean like your other logs.

    Looking at my HJT or other logs, could you please suggest what other processes could be stopped without hampering normal operation?[/quote]Yes I will give you a few things to try but these may not be your main problem. Let's try them and see if there is any improvement.

    First a question. Do you use/relie on InstallShield Update Service that you have running? I'm referring to these two HJT lines:

    O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
    O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup

    Here is what it does? But it also is a waste of system resource to be always running.
    If you don't think you need it, add those two lines to the below list of things to fix with HijackThis.

    Now run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.


    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
    O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
    O4 - HKLM\..\Run: [ScreenPrint32] C:\Program Files\ScreenPrint32 v3\ScreenPrint32.exe -startup
    O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
    O4 - Startup: WordWeb.lnk = C:\Program Files\WordWeb\wweb32.exe
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
    O4 - Global Startup: NkvMon.exe.lnk = C:\Program Files\Nikon\NkView6\NkvMon.exe
    O16 - DPF: {0246ECA8-996F-11D1-BE2F-00A0C9037DFE} (TDServer Control) - http://www.anandabazar.com/wfplayer/tdserver.cab

    After clicking Fix, exit HJT.

    Now reboot and let me know if the above helped.

    If it did not improve things enough, try each of the below:
    1. Uninstall AVG Antispyware and note any level of improvement
    2. Uninstall Google Talk and Google Video Player so we can see if it removes the GoogleUpdaterService that is always running.
    3. Uninstall Symantec to see if it is the cause of your problems.
    After trying all of the above, let me know the results and also run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created. This way I can see your current status.
     
  10. monalisa

    monalisa Private E-2

    I have removed the items that you mentioned from the startup using hijackthis except wordweb, screenprint and the anandabazar.com/wfplayer /tdserver.cab as I use this too often .

    Symantec is the only antivirus that I have provided by the institute I am affiliated to, and I have it for years now, so didnt want to uninstall it .

    The performance is better now, can wait for a few days to see how it goes. But even over the last two days, it seemed to me that the performance (speed) of the laptop was visibly deteriorating for instance it was taking several seconds to just open a jpeg file using windows fax and picture viewer.

    It looks better now - possibly b'coz so many programs were removed.

    Thanks for your suggestions. WOuld like to watch it for a few days and we can go from there.

    A quick qs: Is there a way to test if the hardware ( RAM) is dying or not?

    Thanks.

    Monalisa
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That is a better question to address in the Hardware Forum. You can find various tools available for download on Major Geeks to help with this too. See the below download folders:

    Diagnotics

    Memory


    Any questions you have related to this should be posted in the Hardware Forum.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds