Slow PC/Freezing Screens, Prob with svchost.exe ?

Discussion in 'Malware Help (A Specialist Will Reply)' started by MGfloozy, Feb 6, 2007.

  1. MGfloozy

    MGfloozy Private E-2

    Hi

    I'm looking for a bit of help to understand why my PC's having problems.

    Symptoms :
    - Task Manager shows svchost.exe at 95-98% CPU more times than not
    - Unable to check for Windows update. Screen hangs at the green scrolling checking bar

    I've read and followed the instructions on the Read & Run Me First page and have attached the logs.

    Had a couple of problems while following the instructions :
    - Managed to work in Safe Mode but not Safe Mode with Networking (this was the step just before BitDefender.
    - Had to reboot my PC before I could do the Panda Active Scan
    - No report for Panda ActiveScan as the screen said 'No viruses or other malicious software have been found.

    Would really appreciate some help with this one.
    Cheers
     

    Attached Files:

  2. MGfloozy

    MGfloozy Private E-2

    Last log attached.
     

    Attached Files:

    Last edited: Feb 6, 2007
  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Is this your ISP: PlusNet Technologies Ltd
    Is this your homepage: http://www.baby-greenhouse.co.uk/


    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
    O16 - DPF: {A7EA8AD2-287F-11D3-B120-006008C39542} (CBSTIEPrint Class) - http://offers.brightstreet.com/cif/download/bin/actxcab.cab

    After clicking Fix, exit HJT.

    We will need to flush your system restore when we are sure you are clean.

    Now attach new logs for:

    * GetRunKey
    * ShowNew
    * HJT

    Be sure to tell us how things are running.
     
  4. MGfloozy

    MGfloozy Private E-2

    Thanks for the response; much appreciated.

    Yes, they are my ISP and homepage.

    I've followed the HJ steps and attached a new log, along with the other two.

    After I'd fixed the problems you highlighted, I thought I'd cracked it, but sadly not.
    I can open as many webpages as I like and have Outlook open at the same time.
    The problem is still then when I try and check for Windows updates.

    To make sure I was going to the right update page, I went to Start/Windows Help and Support. Clicked on Custom and noticed that in Task Manager svchost.exe started at 64% and within 5 secs was up to 98%. I left it running for about 10mins but no joy, so closed it down. If I check the Applications tab, it shows it as running.
    It's that slow that if I drag the Task Manager screen it looks like a snake of about 100 of them on the screen.
     

    Attached Files:

  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You have not managed to show hidden files and folders.

    Please copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Attach new logs for:
    GetRun
    ShowNew
    HJT
     
  6. MGfloozy

    MGfloozy Private E-2

    Hope this is right confused
     

    Attached Files:

  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You have alot of programs in your startup ....you may wish to use msconfig to disable those that you don't need (for diagnosis, not to permanently stop!) and see which are slowing down your startup.

    Also, try disabling ZoneAlarm to see if that effects the cpu usage and the MS updating.

    I'm not seeing any malware.

    Repost back.
     
  8. MGfloozy

    MGfloozy Private E-2

    Hi

    Well as least I know I'm clean of malware I guess. That's always got to be a bonus.:)

    I tried both of the tips you suggested but sadly neither seem to make a difference.:cry

    I've even tried killing svchost in task manager but all that seems to do is drop my internet connection.

    If I let it run Microsoft update it's course and then stop the using End Process in Application , when I select Error report I get a pop up telling me I'm not connected even when I know I am.

    Started to wonder if it's something to do with my connection as I couldn't even start up in Safe with Networking ?

    Really not sure what to try next. Any ideas gratefully received
     
  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Download this tool - Pocket KillBox

    Save it to its own folder somewhere that you will be able to locate it.

    Now run Pocket Killbox by doubleclicking on killbox.exe
    Choose Tools > Delete Temp Files and click Delete Selected Temp Files.
    Then after it deletes the files click the Exit (Save Settings) button.

    After it cleans your temp files, if you are still having problems, you may wish to post in the software section, as this is probably not a malware issue.
     
  10. MGfloozy

    MGfloozy Private E-2

    Just wanted to say thanks for all your help.
     
  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Not a problem ....good luck.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds