My PC is crawling again

Discussion in 'Malware Help (A Specialist Will Reply)' started by Denise_M, Sep 2, 2006.

  1. Denise_M

    Denise_M MajorGeek

    Hi,

    Yesterday, my system started to crawl along again. I was reading my email and comparing prices and features of printers when my pc started taking between 30 to 45 seconds to open a page, folder, email, with everything moving choppy and pages were freezing up. I checked Windows Task Manager and under Processes, between 68% to 89% was being used by Explorer, and 100% cpu was being used. Right now, 100% cpu is being used, which leads me to believe that my pc picked up something again or the previous infection wasn't totally removed. I usually don't have any of my external hard drives running. I only turn them on to move a file onto one of them and then I shut it off, so that they're not using any system resources.

    Belarc Report:

    So I started to run the tests again that are mentioned at http://forums.majorgeeks.com/showthread.php?t=35407

    I still can't get BitDefender to run on my pc. I followed the instructions at the BitDefender site and I allowed pop-ups and Active X controls, but it didn't help. Right now, I'm running the Panda Scan.

    In addition to the scans that were requested, I also ran:
    Spyware Doctor . . . no infections found (report is available if needed)
    AVG Scan . . . no infections found (report is available if needed)

    Windows Defender found no infections.

    I'm attaching GetRunKey, ShowNew logs and SpyBot reports to this post. I'll attach the Panda ActiveScan and HijackThis report to the next post.

    The interesting thing I found is that 3 instances of svchost.exe is always running at the same time. Would you let me know if this is normal?

    Denise
     

    Attached Files:

  2. Denise_M

    Denise_M MajorGeek

    I attached Spyware Doctor report instead of SpyBot, so I'm attaching SpyBot and HJT Report to this post.

    Denise
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to run all the steps in the READ ME and you need to not install multiple antivirus applications as the READ ME specifies.
     
  4. Denise_M

    Denise_M MajorGeek

    I've not only read the read me several times but I re-wrote it so that it would be more organized.

    I gave you all the reports that I could get. BitDefender won't run for me and Panda's screen is too large for me to see a button or a link to generate a report. I installed Avast only to run a scan. I don't have it running in the background. I use only Sygate firewall and AVG.

    As I said, I didn't mean to attach the Spyware Doctor report but after 24+ hours of running scans, I confused it with the SpyBot S&D report and attached it and couldn't unattach it.

    The reports that I attached are all the reports that I was able to get.

    Trend Housecall keeps giving me a warning about ASP.NET, and directs me to the Microsoft site.

    This is all the info that I have to give you. If you don't find anything in the reports, in HijackThis or from what I said, my problems may be a software or hardware issue. My pc hasn't been the same since Microsoft snuck in the Tray file.
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It is meant to be run the way it is written not however you rewrote. I guess that would explain why you now have two antivirus applications. You must have left step 3 out of your re-write. You MUST NEVER install two antivirus applications at the same time. This can break the other AV, it makes each one less effective, it slows down you PC, and it can also break your Windows Security Center and possibly make it unfixable. It does not matter whether you are running the scans at the same time or not. You did state your PC is slow. This is one reason for it. Follow the READ ME and you will not have two antivirus applications installed. In addition since you may be running your own copy of the READ ME, it also would explain why you do not have the current version of ShowNew. You are three versions out of date.

    You also have three realtime antispyware applications installed and this is also not recommended for the same reasons as above for an antivirus. You have:
    Spyware Doctor 4.0
    Windows Defender
    Yahoo! Anti-Spy

    Only one of them should be kept on for a permanent solution. If Spyware Doctor is a paid version, keep it and uninstall the others.

    Yes and then you went on to attach an Ad-aware log and said it was a Spybot log too.

    You do not have malware problems! You have end user problems! ;) You have installed too many things that are slowing down your PC.
     
    Last edited: Sep 5, 2006
  6. Denise_M

    Denise_M MajorGeek

    I wrote you a perfect letter but, as usual, MajorGeeks scr*wed up and asked me for my ID and password for the second time and my post disappeared. It'll be in here tomorrow.
     
  7. DavidGP

    DavidGP MajorGeeks Forum Administrator - Grand Pooh-Bah Staff Member

    When logging in tick the Remember Me box. I generally type any replies up in notepad first, that way any mishaps are generally covered for.
     
  8. Denise_M

    Denise_M MajorGeek

    I do, Halo, but it doesn't work, but thanks for the advice.

    I decided not to rewrite the post that disappeared on me last night. I won't try to defend myself except to say that I followed the directions to a T, and the accusations that were lodged against me are false, and I won't argue the matter.

    I'm attaching a copy of the guide that I re-organized. I worked for about 20 years editing guides, brochures, land use manuals and health benefit plans for laymen. The guide that I'm attaching was basically thrown together in about an hour so it's not perfect, but looking at it from the point of view of a person who isn't a pc guru, it makes much more sense and the steps are much easier to follow.

    Denise
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Thanks for attaching your suggestions. I will take a look at it when I have time and see what improvements can be made. One thing you have to realize is that the READ ME is work in progress that changes frequently in order to keep up with malware and it is sometimes difficult for us to completely change the order of steps because, the step numbers are often referred to in other procedures that we use. Changing the READ ME can snowball into changing many other things. However, even as you brought up this topic, I had three new variations of the READ ME in progress. I was not completely happy with any of them all though there were a few improvements in each.


    Are you blocking cookies or deleting them after each online session? If so, that could be your problem. But there are also a few bugs in the V Bulletin code that I have seen effect this area of requiring another login when you are already logged in.
     
  10. Denise_M

    Denise_M MajorGeek

    In a previous post, I had asked
    Is this normal?

    Denise
     
  11. DavidGP

    DavidGP MajorGeeks Forum Administrator - Grand Pooh-Bah Staff Member

    Hi Denise, 3 instances of svchost.exe running at once is quite normal, but do keep an eye for ones that are spelt in a similar way, but have say an 0 for the o or mixed up spelling of the same word ie. scvhost.exe as they could be malware.

    Some info
    http://support.microsoft.com/?kbid=314056
     
  12. Denise_M

    Denise_M MajorGeek

    Ok, thanks Halo.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds