Hi,
You could, as a first measure find out what is going on in your computer by accessing the Task Manager.
To do this:
1 Hold down, on your keyboard, Ctrl, and press Alt and Delete (at the same time)
2 Windows Task Manager should open,
3 Click on the Applications tab at the top of the window
4 A list of applications(programmes) that are are running will appear
5.Click on the tab at the top labelled Processes
6 A list will appear
7 Click on the column header labelled CPU once or twice
8 This shows (in order) the processes that are using your CPU cycles
9 You can enter the names in a search engine (such as Google) for information on them.
10 System Idle Process should be showing a % in the high 90's if you are not running anything in particular.
Hard disc activity at boot up can be caused by anti-virus or anti-spyware or other scheduled activity and the Task Manager will clearly identify this for you.
If you go to
Start/Run and type in
MSCONFIG
The screens that open will give you extra info;
Unless you are familiar with this feature, however, it is best to use it, to seek information, rather than altering any settings.
Regards
paws
Thanks for responding so fast
1- Yes start up scans etc a-side, after startup with firewall set to stop all traffic set, the FileMonitor shows lots of activity.
The harddrive being busy/slow downs are a recent problem.
2- I did what you said and looked at taskmanager and i see alot! of processes? how can i show u them?
Note: its a 2.6 with 1.5 G Ram, no need to write back to hard drive non stop!
Thanks and whats the next step for this hyper active computer problem?
Mike
Hi pac, thanks for the info.
Question could you take a quick look at my hijackthis log i posted to see if you spot anything interesting?
I did find service.exe running in the dell suport dir….hmmm deleted it temperarly anyway…
Hi,
Pacman123 gave you good information and if you follow his advice it will put you on the right track.
I notice that you have posted a HJT log in the "HiJackThis logs and Spyware/Malware forum" the normal procedure there, is to wait 5 days and if you have not received a reply within that timeframe follow the directions in that Forum.
The trained and trusted advisers who operate in that forum often have more folks requesting advice than they can handle immediately and so although it is hard, you will need to try and be patient and wait until one of the advisers (who are volunteers) replies to your log. (or the 5 days are up!)
You may have inadvertantly caused a delay by responding to your own log, (twice) this has the effect of indicating that your log is being "replied to" and therefore being actioned.
I see from your HJT log that you may have already used MSCONFIG, if you have disabled one or more items in "Startup" HJT may not "see" items that may have been disabled in this way and it's usual therefore to run HJT with them running.
Regards
paws
Thanks for your help, i hope i (noob) have not slowed things too much!
Should i change my msconfig back then supply a new hijack log? or just wait?
Thanks again,
Mike
Hi,
I think it may be best just to wait a while for a response from a malware expert in the other forum. If they want to see a fresh HJT log with all startup items running then they will ask.
1 Have you checked for scheduled activity immediately after boot up?
2 You have Norton Ghost installed, do you have an "image" available (together with back up data, if appropriate) which could restore your disc to the state it was in prior to this disc activity starting?
3 Do you have a System Restore Point set up with a date prior to the start of the "disc activity"? (Please do not turn off System Restore at the moment)
Regards
paws
I have not checked activity right after boot> i will.
I use ghost for cloning my second back up hard drive.
Because i use the above backup method i have turned sys-restore off. bad idea?
Thanks for your input.
Mike
Hi tonedef,
I think somewhere earlier, you indicated that this is "new behavior", though that reference may have gotten edited out.
If it is "new", then what changes or new items might you have added recently before the "new behavior"?
You have quite a few security related programs that will be accessing both your machine for scanning and attempting to access the internet for updates, immediately upon booting up.
Since AVG Anti-Spyware is relatively new, I imagine it may be a new add to your machine.
AVG Anti-Spyware is a great utility, but it does launch a scan when you boot, and launches an attempt to find updates at the same time.
SpywareDetector may be doing the same as AVG Anti-Spyware. (Note: until recently, SpywareDetector was considered "rogue-suspect" though it has recently been de-listed) If you have an older version of SpywareDetector, you may have some legacy problems of false detection going on.
It's your choice, but with all the wonderful tools available that have excellent track records, I would not use this program.
You also have Nero/INCD starting at boot time……. INCD is a huge resource hog. Do you actually even use it? INCD is only used in the making and reading of CD-Re-writeable disks. I decided to use only CD-R to make CD's. When I need to update my saved information I just throw away the old CD after making a new one. (about $0.15 US, no biggie) Whereas the CD Re-Writable disks are closer to $1.00 each and people have reported more problems with adding/deleting information from them.
Norton Ghost runs in the background all the time, if you have "incremental" backups set. do you really need that function running, or might you be able to run an image backup manually on a regular basis?
You have a CachemanXP.exe on your machine. Supposedly it is an optimizer to recover RAM and tweak how system cache's are used. In my experience, similar utilities are more load than benefit.
You have a variety of nVidia helper and update utilities running. In my experience, once the user has set their preferred display, the nVidia tray utility is hardly ever touched, and is just sitting their eating up your resources.
You have a variety of Logitech helper utilities. Same comment as above for nVidia.
you have xpnetdiag.exe on your machine, but "files missing". Are you having difficulty setting up your Internet connectivity, or experiencing intermittent connectivity problems. If not, I sure don't know why you'd continue to have this item (though I can't confirm that it consumes resources)
How much RAM do you have on this machine?
With all the above, I sure hope you have a bunch. (at least 1gig)
Even with 1gig of RAM, the above utilities can consume much of your resources, before you even get started with applications.
Since (I think) you are complaining of slow performance and near-constant activity in the background, I'd be suspect of the above items. They are all legitimate and wonderful in their own way, but it is "user choice" for what gets loaded on a machine, and how you want it to operate.
Best Regards
Hi tonedef,
Dough has given you some really good pointers that should help you get things back to normal quickly.
It is a good that you have a Ghost image and backup so that that you can always restore the hard drive to the position it was in before the problem started.
Although a lot of folks tend to leap towards their Windows System Restore Point facility at the first hint of trouble (it is not intended to be used in that way) there is no doubt that on occasions, having a valid Restore Point that allows you to "turn back the clock" to a time before a problem started can be a most valuable tool. For that reason I usually recommend that System Restore is active. If hard disc space is limited then the default value of 12% of disc size can be reduced, the actual amount you need is hard to estimate but reducing to 6% will provide a compromise between hard disc space given up and the ability to store more than one or two Restore Points.
Some malware experts advocate turning off System Restore before cleansing a machine. I do not favour this approach as turning off System Restore purges the computer of all Restore Points and in my view it is better to have a valid and usable Restore Point (even if it restores to a preciously infected state) than to have no Restore Points at all!
Once your machine is completely clean is the time to turn off System Restore to purge your Restore Points which may be harbouring malicious elements; once you have done this, reboot, and turn it on again and immediately create a new clean Restore Point as an "insurance" for the future.
I am sure you are aware that using System Restore does not normally affect most of your data or documents (at least the ones that are safely filed and for example not on your desktop!)
In the meantime follow Dough's excellent advice and do post back and let us know how things are progressing.
Regards
paws
✨ Ask AI
AI can make mistakes. Check the cited posts. Archived advice can be out-of-date
Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI