CPU high usage / slow computer (part vi)

Discussion in 'Malware Help (A Specialist Will Reply)' started by ingopj67, Sep 20, 2011.

  1. ingopj67

    ingopj67 Private E-2

    CPU high usage / slow computer (part iv)

    Hi Thisisu & Admin,

    I have once again tried to reply to the "part ii" post as requested but all I get is "You do not have permission to access this page", so I have no alternative to start a new thread. I cannot understand this, I access other forums with no problems. Is it something to do with the malware cleaning process, I am mystified.

    Anyway, back to the original problem, performance still seem the same to me, only 10% usage with just Firefox open, but load a new page, run itunes, media player just slows. Sound distortion remains. Also about 6 windows updates have run since running the last programmes.
    Thisisu, thanks again for your patience; it seems to be a stubborn problem, any leads on what it might be ?
    Here are the logs:
     

    Attached Files:

  2. thisisu

    thisisu Malware Consultant

    Re: CPU high usage / slow computer (part ii)

    Not seeing anything bad in the new OTL log.

    ESET Online Scanner
    Remember to attach your log from ESET Online Scanner (How to attach items to your post)

    Starting to also think this is partially software related because of the following in Extras.txt:

    Code:
    Error - 19/09/2011 00:22:14 | Computer Name = PJIACER5633 | Source = MPSampleSubmission | ID = 5000
    Description = EventType mptelemetry, P1 80072f78, P2 endsearch, P3 search, P4 3.0.8402.0,
     P5 mpsigdwn.dll, P6 3.0.8402.0, P7 microsoft security essentials (edb4fa23-53b8-4afa-8c5d-99752cca7094),
     P8 NIL, P9 NIL, P10 NIL.
     
    Error - 19/09/2011 13:49:43 | Computer Name = PJIACER5633 | Source = MPSampleSubmission | ID = 5000
    Description = EventType mptelemetry, P1 80072f78, P2 endsearch, P3 search, P4 3.0.8402.0,
     P5 mpsigdwn.dll, P6 3.0.8402.0, P7 microsoft security essentials (edb4fa23-53b8-4afa-8c5d-99752cca7094),
     P8 NIL, P9 NIL, P10 NIL.
    [ System Events ]
    Error - 19/09/2011 13:25:28 | Computer Name = PJIACER5633 | Source = Service Control Manager | ID = 7031
    Description = The COM+ System Application service terminated unexpectedly.  It has
     done this 1 time(s).  The following corrective action will be taken in 1000 milliseconds:
     Restart the service.
     
    Error - 19/09/2011 13:25:28 | Computer Name = PJIACER5633 | Source = Service Control Manager | ID = 7031
    Description = The Microsoft Antimalware Service service terminated unexpectedly.
      It has done this 1 time(s).  The following corrective action will be taken in 
    15000 milliseconds: Restart the service.
     
    Error - 19/09/2011 13:25:28 | Computer Name = PJIACER5633 | Source = Service Control Manager | ID = 7034
    Description = The Intel(R) PROSet/Wireless WiFi Service service terminated unexpectedly.
      It has done this 1 time(s).
     
    Error - 19/09/2011 13:39:42 | Computer Name = PJIACER5633 | Source = Service Control Manager | ID = 7009
    Description = Timeout (30000 milliseconds) waiting for the IMF Service service to
     connect.
     
    Error - 19/09/2011 13:39:42 | Computer Name = PJIACER5633 | Source = Service Control Manager | ID = 7000
    Description = The IMF Service service failed to start due to the following error:
       %%1053
     
    Error - 19/09/2011 13:41:12 | Computer Name = PJIACER5633 | Source = Service Control Manager | ID = 7009
    Description = Timeout (30000 milliseconds) waiting for the Intel(R) PROSet/Wireless
     Event Log service to connect.
     
    Error - 19/09/2011 13:41:12 | Computer Name = PJIACER5633 | Source = Service Control Manager | ID = 7000
    Description = The Intel(R) PROSet/Wireless Event Log service failed to start due
     to the following error:   %%1053
     
    Error - 19/09/2011 13:42:39 | Computer Name = PJIACER5633 | Source = DCOM | ID = 10010
    Description = The server {7F6316B4-4D69-4765-B0A3-B2598F2FA80A} did not register
     with DCOM within the required timeout.
    
    Error - 19/09/2011 13:49:42 | Computer Name = PJIACER5633 | Source = Microsoft Antimalware | ID = 2001
    Description = %%860 has encountered an error trying to update signatures.     New Signature
     Version:      Previous Signature Version: 1.111.2476.0     Update Source: %%859     Update Stage:
     %%852     Source Path: http://www.microsoft.com     Signature Type: %%800     Update Type: %%803
    
    	User:
     NT AUTHORITY\SYSTEM     Current Engine Version:      Previous Engine Version: 1.1.7604.0     Error
     code: 0x80072f78     Error description: The server returned an invalid or unrecognized
     response 

    For troubleshooting purposes, I would uninstall all of the below and see if the same problems occur.

    • Intel(R) PROSet/Wireless WiFi Software
    • Advanced SystemCare 4
    • IObit Malware Fighter
    • Microsoft Antimalware
    • Microsoft Security Client
    • Microsoft Security Essentials
    • Microsoft Application Error Reporting
    • Smart Defrag 2
    • Symantec KB-DocID:2003093015493306
    • Acer Screensaver
    • eSupportQFolder
    • Game Booster 3
    • MarketResearch
     
  3. ingopj67

    ingopj67 Private E-2

    CPU high usage / slow computer (part v)

    Hi Admin,
    Please could you merge with original thread as once again I cannot reply, thanks.

    Hi Thisisu,
    I have run ESET scanner and deleted several of the programmes request, but some I could not locate or computer would not allow a delete.
    Deleted;
    Advanced Care System 4
    IObit Malware Fighter
    Smart Defrag 2
    Acer Screen Saver
    Games Boost 3

    Could NOT Delete
    MS AntiMalware

    Did NOT want to Delete;
    MS Security Essentials (me only realtime antivirus software)
    Intel(R) PROset Wireless WiFi Software (only have access to internet thru wifi)

    Could not locate;
    MS Security Client
    MS Application Error Reporting
    Symantec KB Doc
    eSupportQfolder
    MarketResearch

    The problem still persists.

    Attached is the ESET log
     

    Attached Files:

  4. ingopj67

    ingopj67 Private E-2

    Hi Thisisu,
    Thanks again for all your help, you've been brilliant. :major Bit of a mystery this one, but will have a look at the Software forum as suggested.

    Admin - please merge as I cannot reply to original post
     
  5. thisisu

    thisisu Malware Consultant

    You're welcome. I think it's some problem with MSE. I was only suggesting uninstalling it temporarily to see it resolved your problems. Most of the event log errors were pointing to MSE as the source.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis if it present
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds