Svchost & 100% CPU

Discussion in 'Malware Help (A Specialist Will Reply)' started by jumpforjoy, Feb 23, 2008.

  1. jumpforjoy

    jumpforjoy Private E-2

    I am hoping that I am posting this in the correct place if not please accept my apologies as I am a bit confused after having read tons and tons of posts ( and of course following the directions to the letter).

    About a month ago I began noticing the my Acer Aspire 5050 was running very slowly. I have 1024 M of memeory so I knew it was not that but I had uninstalled Vista wiped the hard drive clean and installed Windows XP and thought perhaps I installed a wrong driver or had a program that didn't install properly. After checking all of this out it looked like when I didn't launch Earthlink's Task Panel but just went onto the web through IE7 things were OK.

    That method worked for about 3 weeks and then things got really quirky. After a reboot I would lose my sound driver, I couldn't launch the web from links within e-mails. IE7 wouldn't launch from either the shortcut on my desk or from the start menu. I too found that if I did the ole Ctrl Alt Delete got to the Task Manager and found the correct svchost.exe and killed the process I would be ok but it seemed to me that this was a problem that should be resolved and I shouldn't use this work around forever.

    I turned to you folks at MajorGeeks because I realize that you are the best in providing step by step instructions.

    I followed all of the steps in the thread Read & Run Me First. I did the Basic Computer Clean up even though I generally runs both CCleaner and multiple Spyware Removers. Nothing was found. I checked that I had only one firewall and anti-virus (both from AVG)
    Next I moved on to 1: House Cleaning & Setup. Using the Malware list and the Rogue List, I checked Add/Remove Programs and found nothing unusual. I set up MsConfig to run in Normal Mode and did a reboot.
    I don't run Norton so didn't need to do these steps but even so I ran a search for any folders or files named quarantine. Ran CCleaner. Already had folders set to see hidden folders.

    Then I ran through the Windows XP Cleaning Procedure. Although my sound driver is not disappearing at each reboot and I am no longer having IE7 difficulties and I can access web links in my e-mail I still have Svchost process that rans at 100% after I re-boot. I have attached my logs as suggested and the only thing I can so that seemed weird when I ran MGTools was I got a message that said "Hitting any key will close MSGTool" and then a line below that it said "Hit any key to continue". I ran the tool twice the first time I hit a key and poof the tool closed up. The second time I left the computer for about 10 minutes and the tools was still displaying these messages so I figured that it was done.

    Thanks Brenda
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Your problems may or may not be malware. I have seen many cases where slow PCs and hogging of system resources was caused by Earthlink's TotalAccess program.

    You missed Viewpoint Media Player. Please uninstall it now.

    I also recommend ( but it is your decision in the end ) uninstalling the below adware which SUPERAntispyware already removed some registry keys for.
    Coupon Printer for Windows
    CouponBar

    You can read more about these in the below links:
    http://vil.mcafeesecurity.com/vil/content/v_134314.htm
    http://www.symantec.com/security_response/writeup.jsp?docid=2005-110315-1439-99
    http://www.ca.com/us/securityadvisor/pest/pest.aspx?id=453076021
    http://www.castlecops.com/tk14374-couponbarie_dll_COUPON_DLL.html

    I'm reviewing your logs now.
     
    Last edited: Feb 23, 2008
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Do you or did you have any programs like below installed at any time:
    Company Name:Wintertree Software Inc.
    File Description:Sentry Spelling-Checker Engine

    I see the below DLL which is supposedly for the above but I don't see this program installed unless it is embedded into something else you use.
    Code:
    "C:\WINDOWS\system32\"
    ssce5332.dll  Jan 26 2008      184320  "ssce5332.dll"
    Based on your logs, your issues are not malware related. I will give you a couple things below that you should do but I suspect that your problems are due to what I already stated about Earthlink's TotalAccess program which is even running a service. I would bet if you uninstall this or at least stop it from loading as a test, you will see a change. Perhaps you should speak to them since I have seen this software widely stated as causing problems.

    Here are some recommended actions you should perform.


    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R3 - URLSearchHook: (no name) - ~CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe"
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O15 - Trusted Zone: http://www.coolsavings.com

    After clicking Fix, exit HJT.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
     
  4. jumpforjoy

    jumpforjoy Private E-2

    Many thanks! I will give all of your suggestions a try and let you know how I make out. Thanks again, Brenda
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Make sure you check to see if TotalAccess is the cause of your slow down.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds