Slow computer with no apparent infection

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Jiroben, May 28, 2011.

  1. Jiroben

    Jiroben Private E-2

    Hi, one of my computers is kinda slow since I started using again, its been about 3 years since it was turned on, had it stored on the closet for that time. Also before I kept it away it was also rather laggy.

    I started using it a few months ago but have not found a solution to having it work normal again. I have let it update to WinXP SP3, ran Avira AV and found 55 viruses (all removed now) also with Malwarebytes (about 44 found), but it still uses about 46% of the cpu accoarding to the task manager and when I use a program it goes near 100%.

    The application that seems to use more cpu is csrss.exe, in the task manager show that about 25 to 30% are in use of the cpu.

    I coudnt run combofix and rootrepeal, but here are the other logs.
    I also have an AdAware antivirus log. Do you guys need it?
    Thanks in advance.
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    What issue did you have trying to run ComboFix?

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Now copy just the bold text below to notepad (Do not include any space above the word REGEDIT). Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Now use windows explorer to find and delete:
    C:\WINDOWS\inf\ceky.dll

    Slowness issues do not have to be malware related.

    Please explain what operations are slow! For example answer the below:

    * Is boot up slow?
    * Is shutdown slow?
    * Is browsing/surfing slow?
    * Is downloading slow?
    * Is running any application?
    * Is it also slow in safe boot mode?
    * Also are any process showing in Task Manager to be using a lot of CPU time?
    * Anything else slow?

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).Make sure that you watch for the license agreement for TrendMicro HijackThis and click on the Accept button TWICE to accept ( yes twice ).

    Then attach the below logs:

    * C:\MGlogs.zip

    Make sure you tell me how things are working now!
     
  3. Jiroben

    Jiroben Private E-2

    I did get a success message from the fixME.reg
    I followed the instructions, but I had some problems.
    I maneged to get up to

    "Now use windows explorer to find and delete:
    C:\WINDOWS\inf\ceky.dll"

    But couldnt do that because couldnt find that file.
    Also while running MGtools/Getlogs.bat I kept getting an error saying something like it couldnt find cmd.dll.
    I still attaching the zip.

    And here are the answers to your previews questions:
    1) With combofix it didnt run when beginning the scan, it showed the message that it will take about 10 min to scan... but it never began scanning, I left it all night running the program but nothing happend.

    2)The booting and shutdown arent slow.
    3)Browsing is not slow on web pages with mostly text, but when I scroll the use of cpu rises to much.
    If I try to view any videos online they lag to much, the use of cpu reaches 100%. Thats kinda the main problem since I want to use this computer for simple video editing.
    4)Aplications run fine.
    5)The programs use of cpu are: csrss.exe about 20 to 30%, one that says SYSTEM goes around 2 to 10%, and the one on the bottom of the list goes from 47% to 67%.

    Also, this computer has 3 sessions, how much does that affect?
    Hope that helps.
     

    Attached Files:

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    My first thought would be to upgrade your Ram to 2gb.

    You need to download Net Framework and see if that helps with getting a proper Newfiles log.

    In the meantime, let me check one more thing, as I am not seeing any malware in your logs as yet.

    Download OTL to your desktop.


    • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
    • Vista and Windows 7 users Right-click OTL and choose Run as Administrator)
    • When the window appears, underneath Output at the top change it to Minimal Output.
    • Check the boxes beside LOP Check and Purity Check.
    • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.


    When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.

    Attach both of these logs into your next reply.
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Nope, it will not help. That is only needed for processdll.exe The runkeys.txt log also shows the problem. See the error messages in the Using MGtools link. I suspect error type 1 or 2.


    You could debug this from the command prompt Tim. ;)
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please click Start, Run, and enter cmd and click OK. This will open a command prompt window. Enter the below commands at the command prompt each followed by the enter key. The bold black are commands. The purple is merely informational.
    cd \MGtools <-- this changes to the MGtools folder and the prompt should change to C:\MGtools>
    GetRunKey <-- this will try to run all one scan from MGtools. Tell me what error messages, if any, you see.
    ShowNew <-- this will try to run all another scan from MGtools. Tell me what error messages, if any, you see.

    What does this mean:
    this computer has 3 sessions
     
  7. Jiroben

    Jiroben Private E-2

    I meant is that this computer has 3 users registered, this computer is in spanish so I mis-translated.

    Here are the new logs from the last scans; also the error I get when I run MGtools, Im translating it the way it suppose to be, hope you can understand.

    subsistem ms-dos 16 bit
    c:\WINDOWS\system32\cmd.exe - getrunkey
    c:\ARCHIv-1\symantec\S32EVNT1.DLL. "Error of a driver of virtual devices trying to start the DLL.
    choose start to end the operation.
     

    Attached Files:

  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    The only thing I can suggest is that you double your amount of RAM. We can remove a few things. but I doubt it will help with your speed issues. That would be something to further discuss in the software forum.

    Download OTM by Old Timer and save it to your Desktop.




    Code:
    :Processes
    explorer.exe
    
    :Files
    C:\WINDOWS\Tasks\hdtqs.job
    C:\WINDOWS\Tasks\jahkf.job
    C:\WINDOWS\Tasks\jappyupo.job
    C:\WINDOWS\Tasks\jjk.job
    C:\WINDOWS\Tasks\jviy.job
    C:\WINDOWS\Tasks\lallmiyj.job
    C:\WINDOWS\Tasks\lxofx.job
    C:\WINDOWS\Tasks\ndjrdt.job
    C:\WINDOWS\Tasks\obvgmw.job
    C:\WINDOWS\Tasks\rjrqppic.job
    C:\WINDOWS\Tasks\udeuzgn.job
    C:\WINDOWS\Tasks\ujpjso.job
    C:\WINDOWS\Tasks\whb.job
    C:\WINDOWS\Tasks\wtz.job
    C:\WINDOWS\Tasks\wvudre.job
    C:\WINDOWS\Tasks\xwe.job
    C:\WINDOWS\Tasks\xwg.job
    
    :Commands
    [purity]
    [ResetHosts]
    [createrestorepoint]
    [emptytemp]
    [start explorer]
    [Reboot]

    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar) and choose Paste.
    • Push the large http://farm3.static.flickr.com/2782/4174320048_f01c448b32_o.png button.
    • OTM may ask to reboot the machine. Please do so if asked.
    • Copy everything in the Results window (under the green bar), and paste it in your next reply.


    Now navigate to the C:\_OTM\MovedFiles folder ( assuming your Windows drive is C). This is where your log will be saved in the form of Date and Time mmddyyyy_hhmmss.log. Just look for the most recent .log file. Attach this log file to your next message.
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    As I suggested in my previous message, see the fix for Error Type # 2 in the below link which was given in the READ & RUN ME:

    Using MGtools
     
  10. Jiroben

    Jiroben Private E-2

    Done the last two steps, here are my logs.
    I also fixed the MGtools problem, Im posting the logs to.

    Also you said that this might not be a malware problem, should this forum would be redirected or where do I make a new thread.

    I think that the problem is more of the use of cpu rather than been slow, the thing is that I cant do much since it goes to 100% very easily, so the solution Im looking for is to reduce the use of cpu so I can multitask better.
     

    Attached Files:

  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I am not finding any malware in your logs. I suggest that you post in the software forum to try to further diagnose your issues. Your logs are clean.

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.We recommend them for doing backup scans when you suspect a malware infection.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.


    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    10. After doing the above, you should work thru the below link:


    Malware removal from a National Chain = $149
    Malware removal from MajorGeeks = $0

    Help Support MajorGeeks
    Buy Discounted Software @ Majorgeeks Store. Giveaways Too!

    Majorgeeks Geek Wear. Hats, T-Shirts, Hoodies

    MajorGeeks on FaceBook
     
  12. Jiroben

    Jiroben Private E-2

    Thank you very much TimW, I appreciate your services and you are a Jedi master or is it Sith lord? any way "the Force is strong with you".
    Chaslang, thanks for the help. You can also be a Jedi master or Sith lord.

    Thanks again and have a good day.
     
  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are most welcome. I will try to keep an eye on your thread in the software forum. Good luck. ;)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds