Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

I suspect a malware in GNR.EXE or GRN.EXE files


  • Please log in to reply

#61
paulgleave

paulgleave

    Member

  • Topic Starter
  • Member
  • PipPip
  • 49 posts
Hi Mate here is process explorer log..
Thanks again

Edited by paulgleave, 31 July 2011 - 04:09 AM.

  • 0

Advertisements


#62
RKinner

RKinner

    Malware Expert

  • Expert
  • 24,625 posts
  • MVP
Don't see the process Explorer log.
  • 0

#63
paulgleave

paulgleave

    Member

  • Topic Starter
  • Member
  • PipPip
  • 49 posts
Hi Ron,
The attach part didn't work. Sorry

Attached Files


  • 0

#64
RKinner

RKinner

    Malware Expert

  • Expert
  • 24,625 posts
  • MVP
This line is bad:

Interrupts n/a 4.62 0 K 0 K Hardware Interrupts and DPCs

Try removing the main battery from the laptop. Then run Process Explorer again as before.

Ron
  • 0

#65
paulgleave

paulgleave

    Member

  • Topic Starter
  • Member
  • PipPip
  • 49 posts
Hi Ron,
Its a desk top computer?

Regards
Paul
  • 0

#66
RKinner

RKinner

    Malware Expert

  • Expert
  • 24,625 posts
  • MVP
Guess we can't fix it the easy way then.

Start Run, msconfig, OK
Go to Services tab and click on the box to hide Microsoft Services then uncheck
everything that remains. Go to Startup tab and uncheck everything. OK and
reboot. Run Process Explorer and see if the Interrupts n/a line drops (usually it is below 1)
If it looks better then go back into msconfig and check about half of the things you unchecked earlier and reboot. If the line goes high again then the culprit was one fo the items you just checked. Go back and uncheck half of the one you checked and try again. Keep at it until you locate the program that causes the Interrupts n/a line to go high.
  • 0

#67
paulgleave

paulgleave

    Member

  • Topic Starter
  • Member
  • PipPip
  • 49 posts
Hi Ron,

I did as you said but had no joy, they all went down to <0.01 after the start up had finished. It did take about 3 mins for start up to finish.
What do you think?
Regards
Paul
  • 0

#68
RKinner

RKinner

    Malware Expert

  • Expert
  • 24,625 posts
  • MVP
How long does it take to reboot if you:

Run msconfig, go to Services tab and click on the box to hide Microsoft Services then uncheck
everything that remains. Go to Startup tab and uncheck everything. OK and
reboot.

If it is much faster then start checking things and rebooting until you find out what is really slowing down the boot.

Ron
  • 0

#69
paulgleave

paulgleave

    Member

  • Topic Starter
  • Member
  • PipPip
  • 49 posts
Hi Ron,

it takes about 4.30 mins to start up and ready to use with all unchecked start up, and about 5.30mins to start up in normal mode?
what do you think?
Regards Paul
  • 0

#70
RKinner

RKinner

    Malware Expert

  • Expert
  • 24,625 posts
  • MVP
Seems awfully slow. You have plenty of memory and its not overheated. Let's look at the logs again:

Start, Run, eventvwr.msc, OK to bring up the Event Viewer. Right click on System and Clear All Events, No (we don't want to save the old log), OK. Repeat for Application. Reboot.


1. Please download the Event Viewer Tool by Vino Rosso
http://images.malwar...om/vino/VEW.exe
and save it to your Desktop:
2. Double-click VEW.exe
3. Under 'Select log to query', select:

* System
4. Under 'Select type to list', select:
* Error
* Warning


Then use the 'Number of events' as follows:


1. Click the radio button for 'Number of events'
Type 20 in the 1 to 20 box
Then click the Run button.
Notepad will open with the output log.


Please post the Output log in your next reply then repeat but select Application.

Ron
  • 0

Advertisements


#71
paulgleave

paulgleave

    Member

  • Topic Starter
  • Member
  • PipPip
  • 49 posts
Hi Ron,

Here is the log.

regards
Paul

Vino's Event Viewer v01c run on Windows XP in English
Report run at 05/08/2011 7:11:07 PM

Note: All dates below are in the format dd/mm/yyyy

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
'System' Log - error Type
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
'System' Log - warning Type
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
  • 0

#72
RKinner

RKinner

    Malware Expert

  • Expert
  • 24,625 posts
  • MVP
Check the Device Manager for problems:
(Start) then rightclick on My Computer and select Manage. Then Device Manager. View, Show Hidden Drivers,
click on each of the + marks in the right pane to open each item. Look for yellow marked items and
uninstall them or delete them and reboot. Do they come back with yellow marks?

Ron
  • 0

#73
paulgleave

paulgleave

    Member

  • Topic Starter
  • Member
  • PipPip
  • 49 posts
Hi Ron,

None with yellow marked items?

When my computer is up and going after the slow start up. it is running well. best it has been in years. So have to say thanks for that.

let me know what you think.
Regards
Paul
  • 0

#74
RKinner

RKinner

    Malware Expert

  • Expert
  • 24,625 posts
  • MVP
Download the free 30 day trial of Bootlog XP

http://download.cnet...4-10864629.html

and install it. Then when it boots you should be able to get a chart showing how long each program or whatever takes to load.

Ron
  • 0

#75
paulgleave

paulgleave

    Member

  • Topic Starter
  • Member
  • PipPip
  • 49 posts
Hi Ron,

Sorry I have been away for a few days. I did the boot download and it went for 12mins. I could not see from the software what was the problem, I think it the lack of geek in me.. :)

I do have a log but its huge.
What would you suggest.
Regards
Paul
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP