techPowerUp! Forums

Go Back   techPowerUp! Forums > Software > General Software

Reply
 
Thread Tools
Old Feb 10, 2013, 03:33 PM   #1
de.das.dude
3500 Posts
 
de.das.dude's Avatar
 
Join Date: Jun 2010
Location: Wild Wild East
Posts: 4,854 (4.40/day)
Thanks: 2,443
Thanked 1,417 Times in 976 Posts
Send a message via Skype™ to de.das.dude

System Specs

Weird Stuff happening, not much hair left in my head to tear off at this point!

This started after the local cable operator leased out the network to a different ISP. this ISP is worse than the previous one.


First, my computer seems extremely sluggish when connected to the net now.
even the desktop hangs. i may have found the culprit:-



sometimes if i end the process, it will end, but come back again. sometimes, trying to end it will trash the system. mouse and kb will work, along with the start button, but nothing else works. Even Alt+Ctrl+Del shows an error.

The appearance changed automatically and its gotten stuck at that. Some elements in the windows like buttons etc, are all square and classic, like in win98. They dont go back to normal, even after restarting, or fiddling with their settings. even applications like CCleaner, IE and opera and and all that i can think of seems to be affected. Even this tab too!

the title bar at the top of the window isnt supposed to be there (and other things)!

Sometimes after the system has locked up, if i press the reset button, it doesnt work either. Other times, if i long press the power button, the monitor goes off, but the CPU keeps running.


Note: this all started after i changed my network settings to match the new ISP, and logged in.

before this everything was allright. but during the changeover of the ISP, my comp did get sluggish if the ethernet cable was connected. however it didnt cause any other problems. comp went to normal as soon as i unplugged cable.


i tested my HDD, RAM, they are both ok. No viruses, checked with eset, updated.

what is going on


Oh and i am getting 8mbps download and 2mbps up during speedtest.net to the neighboring country and while download few things like opera, chrome, but other than these i am getting only 50kbps speed!
__________________
de.das.dude is online now  
Reply With Quote
Old Feb 10, 2013, 03:47 PM   #2
ruff0r
75 Posts
 
ruff0r's Avatar
 
Join Date: Dec 2012
Posts: 116 (0.63/day)
Thanks: 6
Thanked 21 Times in 20 Posts

System Specs

Quote:
Originally Posted by de.das.dude View Post
Note: this all started after i changed my network settings to match the new ISP, and logged in.
You can identify what's using the memory by running the Win7 Resource Monitor:

- Ctl-Shift-Esc to start Task Manager
- Click the "Performance" Tab
- Click the "Resource Monitor..." button at the lower right

In the resource monitor, click the "memory" tab and then click on the "Working Set" column heading to sort by the amount of physical memory being used by the various processes.

Second attempt:
Disable the Superfetch service.
ruff0r is offline  
Reply With Quote
Old Feb 10, 2013, 03:59 PM   #3
McSteel
200 Posts
 
McSteel's Avatar
 
Join Date: Nov 2012
Location: North Disturbia
Posts: 299 (1.41/day)
Thanks: 5
Thanked 138 Times in 101 Posts

System Specs

This smells like a virus. I see you have something from ESET installed (icon in the systray), and it probably wants to update (yellow alert). I suggest you do update it, and run an in-depth scan. You might find an uninvited guest resident...
__________________
Careful what you wish for... You just might get it.
McSteel is offline  
Reply With Quote
Old Feb 10, 2013, 04:01 PM   #4
FordGT90Concept
"I go fast!1!11!1!"
 
FordGT90Concept's Avatar
 
Join Date: Oct 2008
Location: IA, USA
Posts: 10,651 (6.23/day)
Thanks: 1,787
Thanked 2,632 Times in 1,986 Posts

System Specs

Use Process Explorer to see what services are hosted on that svchost.exe.

Edit: if it doesn't list processes under svchost that's taking all the memory, open svchost, go to the "Services" tab to find the services running on the host. The "Threads" tab may also be of some use for when the CPU load spikes.
__________________
Golden Rule of Programming: Never assume.

try { SteamDownload(); }
catch (Steamception ex) { RageQuit(); }

Last edited by FordGT90Concept; Feb 10, 2013 at 04:17 PM.
FordGT90Concept is offline  
Crunching for Team TPU
Reply With Quote
The Following User Says Thank You to FordGT90Concept For This Useful Post:
Old Feb 10, 2013, 04:05 PM   #5
de.das.dude
3500 Posts
 
de.das.dude's Avatar
 
Join Date: Jun 2010
Location: Wild Wild East
Posts: 4,854 (4.40/day)
Thanks: 2,443
Thanked 1,417 Times in 976 Posts
Send a message via Skype™ to de.das.dude

System Specs

Quote:
Originally Posted by McSteel View Post
This smells like a virus. I see you have something from ESET installed (icon in the systray), and it probably wants to update (yellow alert). I suggest you do update it, and run an in-depth scan. You might find an uninvited guest resident...
its updated. yellow cuz its gonna expire in a week.
__________________
de.das.dude is online now  
Reply With Quote
Old Feb 10, 2013, 04:23 PM   #6
de.das.dude
3500 Posts
 
de.das.dude's Avatar
 
Join Date: Jun 2010
Location: Wild Wild East
Posts: 4,854 (4.40/day)
Thanks: 2,443
Thanked 1,417 Times in 976 Posts
Send a message via Skype™ to de.das.dude

System Specs

Quote:
Originally Posted by FordGT90Concept View Post
Use Process Explorer to see what services are hosted on that svchost.exe.

Edit: if it doesn't list processes under svchost that's taking all the memory, open svchost, go to the "Services" tab to find the services running on the host. The "Threads" tab may also be of some use for when the CPU load spikes.
i did try to go to the services, and it listed Winmgnt and another one. i will confirm the other one. BTW, neither looked suspicious.


did a speedtest right now


and i am getting 50KBps downloads :\
__________________

Last edited by de.das.dude; Feb 10, 2013 at 04:29 PM.
de.das.dude is online now  
Reply With Quote
Old Feb 10, 2013, 04:33 PM   #7
de.das.dude
3500 Posts
 
de.das.dude's Avatar
 
Join Date: Jun 2010
Location: Wild Wild East
Posts: 4,854 (4.40/day)
Thanks: 2,443
Thanked 1,417 Times in 976 Posts
Send a message via Skype™ to de.das.dude

System Specs



wtf. well, this isnt normal is it?
__________________
de.das.dude is online now  
Reply With Quote
Old Feb 10, 2013, 04:49 PM   #8
natr0n
1000 Posts
 
natr0n's Avatar
 
Join Date: Jan 2012
Location: FL,USA
Posts: 1,172 (2.31/day)
Thanks: 261
Thanked 597 Times in 311 Posts

System Specs

Wise-Game-Booster

try this will close off uneeded services and anything overtaking resources.

add this to ccleaner directory

cleans up extra sh!t
__________________

My Youtube Channel
natr0n is offline  
Reply With Quote
The Following User Says Thank You to natr0n For This Useful Post:
Old Feb 10, 2013, 04:50 PM   #9
Black Panther
Senior Moderator™
 
Black Panther's Avatar
 
Join Date: May 2007
Posts: 7,114 (3.22/day)
Thanks: 2,177
Thanked 1,853 Times in 1,110 Posts

System Specs

Do you still get that high usage if you boot in safe mode?
Black Panther is online now  
Reply With Quote
The Following User Says Thank You to Black Panther For This Useful Post:
Old Feb 10, 2013, 05:00 PM   #10
Radical_Edward
2000 Posts
 
Radical_Edward's Avatar
 
Join Date: Jan 2010
Location: Oregon, USA
Posts: 3,143 (2.53/day)
Thanks: 2,560
Thanked 1,964 Times in 1,073 Posts

System Specs

Run a malwarebyte's and a TDSSkiller scan. From then info you've given you have an infection.
Radical_Edward is offline  
Reply With Quote
The Following User Says Thank You to Radical_Edward For This Useful Post:
Old Feb 10, 2013, 05:13 PM   #11
de.das.dude
3500 Posts
 
de.das.dude's Avatar
 
Join Date: Jun 2010
Location: Wild Wild East
Posts: 4,854 (4.40/day)
Thanks: 2,443
Thanked 1,417 Times in 976 Posts
Send a message via Skype™ to de.das.dude

System Specs

Quote:
Originally Posted by natr0n View Post
Wise-Game-Booster

try this will close off uneeded services and anything overtaking resources.

add this to ccleaner directory

cleans up extra sh!t
i just copy pasted it into the program files directory
__________________
de.das.dude is online now  
Reply With Quote
Old Feb 10, 2013, 05:15 PM   #12
FordGT90Concept
"I go fast!1!11!1!"
 
FordGT90Concept's Avatar
 
Join Date: Oct 2008
Location: IA, USA
Posts: 10,651 (6.23/day)
Thanks: 1,787
Thanked 2,632 Times in 1,986 Posts

System Specs

Windows Search and SuperFetch both can take huge amounts of memory. Try stopping those services and see if it settles down.

...also ironic that you're having network problems and WLAN AutoConfig and Windows Driver Foundation are running on that process...
__________________
Golden Rule of Programming: Never assume.

try { SteamDownload(); }
catch (Steamception ex) { RageQuit(); }
FordGT90Concept is offline  
Crunching for Team TPU
Reply With Quote
The Following User Says Thank You to FordGT90Concept For This Useful Post:
Old Feb 10, 2013, 05:16 PM   #13
natr0n
1000 Posts
 
natr0n's Avatar
 
Join Date: Jan 2012
Location: FL,USA
Posts: 1,172 (2.31/day)
Thanks: 261
Thanked 597 Times in 311 Posts

System Specs

Quote:
Originally Posted by de.das.dude View Post
i just copy pasted it into the program files directory
It should be saved as Winapp2.ini
__________________

My Youtube Channel
natr0n is offline  
Reply With Quote
The Following User Says Thank You to natr0n For This Useful Post:
Old Feb 10, 2013, 05:19 PM   #14
de.das.dude
3500 Posts
 
de.das.dude's Avatar
 
Join Date: Jun 2010
Location: Wild Wild East
Posts: 4,854 (4.40/day)
Thanks: 2,443
Thanked 1,417 Times in 976 Posts
Send a message via Skype™ to de.das.dude

System Specs

Quote:
Originally Posted by natr0n View Post
It should be saved as Winapp2.ini
"save linked content as"
__________________
de.das.dude is online now  
Reply With Quote
Old Feb 10, 2013, 05:21 PM   #15
de.das.dude
3500 Posts
 
de.das.dude's Avatar
 
Join Date: Jun 2010
Location: Wild Wild East
Posts: 4,854 (4.40/day)
Thanks: 2,443
Thanked 1,417 Times in 976 Posts
Send a message via Skype™ to de.das.dude

System Specs

Quote:
Originally Posted by FordGT90Concept View Post
Windows Search and SuperFetch both can take huge amounts of memory. Try stopping those services and see if it settles down.

...also ironic that you're having network problems and WLAN AutoConfig and Windows Driver Foundation are running on that process...
i was suspecting driver conflict too, but this combination of lan card and wifi dongle has been with me for quite some time now. plus that doesnt explain all the other crazy shit thats happening.
__________________
de.das.dude is online now  
Reply With Quote
Old Feb 10, 2013, 05:22 PM   #16
de.das.dude
3500 Posts
 
de.das.dude's Avatar
 
Join Date: Jun 2010
Location: Wild Wild East
Posts: 4,854 (4.40/day)
Thanks: 2,443
Thanked 1,417 Times in 976 Posts
Send a message via Skype™ to de.das.dude

System Specs

Quote:
Originally Posted by Radical_Edward View Post
Run a malwarebyte's and a TDSSkiller scan. From then info you've given you have an infection.
doind that now. never had to use malwarebytes before. or the other one.

malwarebytes detected two thingys.
__________________
de.das.dude is online now  
Reply With Quote
Old Feb 10, 2013, 05:27 PM   #17
FordGT90Concept
"I go fast!1!11!1!"
 
FordGT90Concept's Avatar
 
Join Date: Oct 2008
Location: IA, USA
Posts: 10,651 (6.23/day)
Thanks: 1,787
Thanked 2,632 Times in 1,986 Posts

System Specs

I would go down the list of those services and stop them in services.msc until you find the culprit. None of those processes should be consuming over 1 GiB of RAM so if you stop one and that memory is freed up, you found one of your problems.


Edit: Also, stop all anti-virus software and firewalls. They can cause a trainwreck. If you're concerned about being exposed to the filthy internet, unplug the internet connection first (you should probably do that anyway to isolate your local problems).
__________________
Golden Rule of Programming: Never assume.

try { SteamDownload(); }
catch (Steamception ex) { RageQuit(); }
FordGT90Concept is offline  
Crunching for Team TPU
Reply With Quote
The Following User Says Thank You to FordGT90Concept For This Useful Post:
Old Feb 10, 2013, 05:42 PM   #18
de.das.dude
3500 Posts
 
de.das.dude's Avatar
 
Join Date: Jun 2010
Location: Wild Wild East
Posts: 4,854 (4.40/day)
Thanks: 2,443
Thanked 1,417 Times in 976 Posts
Send a message via Skype™ to de.das.dude

System Specs

woot. deleted two of the malwares and the appearance change has been fixed. now eveything looks normal. but that service is still here.

Ford can you give me more details about this services.msc?


also, i think the login page of this ISP is infected. because whenever i try to open that page that weird stuff starts happening.
__________________
de.das.dude is online now  
Reply With Quote
Old Feb 10, 2013, 05:47 PM   #19
de.das.dude
3500 Posts
 
de.das.dude's Avatar
 
Join Date: Jun 2010
Location: Wild Wild East
Posts: 4,854 (4.40/day)
Thanks: 2,443
Thanked 1,417 Times in 976 Posts
Send a message via Skype™ to de.das.dude

System Specs

Sweet JC! look at all these services associated with that svchost this time!


EDIT: zing found another malware!

Kudos to Rad Edward for suggesting this.
__________________
de.das.dude is online now  
Reply With Quote
Old Feb 10, 2013, 05:53 PM   #20
de.das.dude
3500 Posts
 
de.das.dude's Avatar
 
Join Date: Jun 2010
Location: Wild Wild East
Posts: 4,854 (4.40/day)
Thanks: 2,443
Thanked 1,417 Times in 976 Posts
Send a message via Skype™ to de.das.dude

System Specs

oh no it went back to the previous form.

the fight continues
__________________
de.das.dude is online now  
Reply With Quote
Old Feb 10, 2013, 05:55 PM   #21
Radical_Edward
2000 Posts
 
Radical_Edward's Avatar
 
Join Date: Jan 2010
Location: Oregon, USA
Posts: 3,143 (2.53/day)
Thanks: 2,560
Thanked 1,964 Times in 1,073 Posts

System Specs

Also run TDSSKiller. There might be something Malwarebyte's is missing. You said that you got this off your ISP's site, do they by chance use Java?
Radical_Edward is offline  
Reply With Quote
The Following User Says Thank You to Radical_Edward For This Useful Post:
Old Feb 10, 2013, 05:56 PM   #22
natr0n
1000 Posts
 
natr0n's Avatar
 
Join Date: Jan 2012
Location: FL,USA
Posts: 1,172 (2.31/day)
Thanks: 261
Thanked 597 Times in 311 Posts

System Specs

Backup data and fresh install is what I do in situations like this.
__________________

My Youtube Channel
natr0n is offline  
Reply With Quote
The Following User Says Thank You to natr0n For This Useful Post:
Old Feb 10, 2013, 05:57 PM   #23
de.das.dude
3500 Posts
 
de.das.dude's Avatar
 
Join Date: Jun 2010
Location: Wild Wild East
Posts: 4,854 (4.40/day)
Thanks: 2,443
Thanked 1,417 Times in 976 Posts
Send a message via Skype™ to de.das.dude

System Specs

Quote:
Originally Posted by Radical_Edward View Post
Also run TDSSKiller. There might be something Malwarebyte's is missing. You said that you got this off your ISP's site, do they by chance use Java?
YES!!!!!!!!

and there is this pop up with the jsp extention(java) that keeps wanting to come up. but opera is blocking it.

i knew this couldnt be a coincidence.
__________________
de.das.dude is online now  
Reply With Quote
Old Feb 10, 2013, 05:59 PM   #24
de.das.dude
3500 Posts
 
de.das.dude's Avatar
 
Join Date: Jun 2010
Location: Wild Wild East
Posts: 4,854 (4.40/day)
Thanks: 2,443
Thanked 1,417 Times in 976 Posts
Send a message via Skype™ to de.das.dude

System Specs

Quote:
Originally Posted by natr0n View Post
Backup data and fresh install is what I do in situations like this.
i really dont know how to do that. never backed up. i usually fresh install. but i really need to backup this time! thanks beforehand
__________________
de.das.dude is online now  
Reply With Quote
Old Feb 10, 2013, 06:25 PM   #25
FordGT90Concept
"I go fast!1!11!1!"
 
FordGT90Concept's Avatar
 
Join Date: Oct 2008
Location: IA, USA
Posts: 10,651 (6.23/day)
Thanks: 1,787
Thanked 2,632 Times in 1,986 Posts

System Specs

Quote:
Originally Posted by de.das.dude View Post
Ford can you give me more details about this services.msc?
It's the same as going to Control Panel -> Administrative Tools -> Services.


Quote:
Originally Posted by de.das.dude View Post
and there is this pop up with the jsp extention(java) that keeps wanting to come up. but opera is blocking it.

i knew this couldnt be a coincidence.
That happens everytime I update Java. I block it everytime.
__________________
Golden Rule of Programming: Never assume.

try { SteamDownload(); }
catch (Steamception ex) { RageQuit(); }
FordGT90Concept is offline  
Crunching for Team TPU
Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Weird Stuff with this Q9550 guitarfreaknation Overclocking & Cooling 4 Jul 10, 2010 11:49 AM
Going wc is this kit a good jumping off point? DriedFrogPills Overclocking & Cooling 12 May 28, 2010 01:27 PM
Can't get my head round all this new nvidia stuff DrPepper NVIDIA 6 Jun 26, 2008 04:16 PM
Weird stuff happening Keiki General Software 2 May 29, 2006 01:05 PM
Really weird stuff happening GeneralDodo Motherboards & Memory 13 Apr 24, 2006 01:33 PM


All times are GMT. The time now is 06:25 PM.


Powered by vBulletin® Version 3.8.6
Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
no new posts