Archived from groups: microsoft.public.windowsxp.perform_maintain (More info?)
Hi,
I have a new laptop with XP family edition. Recently it has been running
very slowly, and task manager shows the culprit using over 90% of the CPU
useage as... taskmgr.exe! Needless to say antivirus (Norton) and antispam
(various) are all upto date and show no anomalies (in safe and std mode).
There is no problem in safe mode, and I have tried to reduce things to a min
in std mode.
Any ideas would be great as I have spent the best part of 2 days on this and
my work is pilling up.
Ian
Archived from groups: microsoft.public.windowsxp.perform_maintain (More info?)
Hi *Ian Brodie* :
> Hi,
> I have a new laptop with XP family edition. Recently it has been running
> very slowly, and task manager shows the culprit using over 90% of the CPU
> useage as... taskmgr.exe! Needless to say antivirus (Norton) and antispam
> (various) are all upto date and show no anomalies (in safe and std mode).
> There is no problem in safe mode, and I have tried to reduce things to a min
> in std mode.
> Any ideas would be great as I have spent the best part of 2 days on this and
> my work is pilling up.
> Ian
taskmgr.exe or taskmngr.exe or ...?
The first is the real Task Manager process and the other is the WormRBOT.Y
May be this worm or an other malware ...
Archived from groups: microsoft.public.windowsxp.perform_maintain (More info?)
No it's definetly taskmgr.exe. But thanks for the links.
My gut feeling is that it's a spamware of some kind trying to connect to the
internet, and as we are in the middle of the french country side we do not
have any high speed connexions.
Archived from groups: microsoft.public.windowsxp.perform_maintain (More info?)
Hi *Ian Brodie* :
> No it's definetly taskmgr.exe. But thanks for the links.
> My gut feeling is that it's a spamware of some kind trying to connect to the
> internet, and as we are in the middle of the french country side we do not
> have any high speed connexions.
Strange...
Are you sure that's the task manager itself, not somethings else ?
2) Make a scan with HijackThis and post the copy of the scanning
log here so I 'll check it and tell you if you have to remove some
stuff there : malwares or useless stuff.
http://www.hijackthis.de/en
--
Claude LaFrenière [MVP] :-)
«My Principal Design Was To Inform, Not To Amuse Thee.»
Lemuel Gulliver, The Travels (IV:12)
http://climenole.serendipia.net
Archived from groups: microsoft.public.windowsxp.perform_maintain (More info?)
Hi Claude,
Here is the Hijackthis log. There are a couple of this that look suspiceous
to me, those in exe in the system32 folder. One last point, I have created
another user profile on this PC and after some halse, and running spyware
etc... now works as it should do. However the first user profile is still
running very badly. I am able to work OK, but I want to clear everything up
as I can see that this new profile will also go down. The log was obviously
run on the bad profile.
Thanks Ian
Logfile of HijackThis v1.99.1
Scan saved at 16:56:08, on 08/06/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2900.2180)
> Hi *Ian Brodie* :
>
> > No it's definetly taskmgr.exe. But thanks for the links.
> > My gut feeling is that it's a spamware of some kind trying to connect to the
> > internet, and as we are in the middle of the french country side we do not
> > have any high speed connexions.
>
> Strange...
>
> Are you sure that's the task manager itself, not somethings else ?
>
> 1) Double check with Process Explorer :
> http://www.sysinternals.com/Utilit [...] lorer.html >
>
> 2) Make a scan with HijackThis and post the copy of the scanning
> log here so I 'll check it and tell you if you have to remove some
> stuff there : malwares or useless stuff.
> http://www.hijackthis.de/en >
> > --
> Claude LaFrenière [MVP] :-)
>
> «My Principal Design Was To Inform, Not To Amuse Thee.»
> Lemuel Gulliver, The Travels (IV:12)
> http://climenole.serendipia.net >
>
Archived from groups: microsoft.public.windowsxp.perform_maintain (More info?)
Hi *Ian Brodie* :
> Hi Claude,
>
> Here is the Hijackthis log. There are a couple of this that look suspiceous
> to me, those in exe in the system32 folder. One last point, I have created
> another user profile on this PC and after some halse, and running spyware
> etc... now works as it should do. However the first user profile is still
> running very badly. I am able to work OK, but I want to clear everything up
> as I can see that this new profile will also go down. The log was obviously
> run on the bad profile.
It was a very good idea to create an other user account for troubleshooting
:-)
This is the result of my analysis:
a) no malwares
b) indexation service useless #1 To be disabled ...
c) What is "\Talkway\vmtalk.exe" ? Found no information about this.
Usefull or not ? #2
d) Too much manufacturer utilities are runnings (as usual ;-) ).
Check if you really need them.
May be the problem with the task manager comes from the combination
of the indexing service and some of those utilities...
Also check the parameters of your anti-virus. Set it to the "default"
to see if there is a difference...
As you say in your post : an other user run with no problem.
The difference comes from utilities not loaded in the new account.
Isn't ?
Disable most of those utilities and check if there are really usefull.
Check also for some "personalisations" in this user account :
Screen Saver, Nice display, etc.
This tool will be easier than msconfig to *disabled* things
in the problematic user accountonly unchecked the suspect items...)
This is the Indexation service.Takes a lot of resources and not really
efficent.
It can be used with the search assistant in the windows explorer
but you can disable this option.
To access the Indexation service and set it to a lower priority :
Start | Run | ciadv.msc
right click on Indexation service | all tasks | performances setup
choose minimum... to use lower system resources.
OR (better)
Set this service to disabled:
Start | Run | services.msc
select Indexation service | button "stop" and choose "disabled".
This is an additional configuration for TouchPad :
if you don't use it it can be in manual start
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
May be essential for the TouchPad.Leave it automatic.
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
4) ***
Updates for Sun Microsystem Java.It's important to keep Java up-to-date
but is it necessary to launched this every days ?
You can check the updates within the Java Applet in the Control Panel.
You are about to answer a thread that has been inactive for more than 6 months. If you still wish to proceed, please ensure that your posting is original and does not duplicate or overlap any prior responses to this thread.