Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

rootkit please help


  • This topic is locked This topic is locked

#31
zep516

zep516

    Trusted Helper

  • Malware Removal
  • 8,093 posts
I missed your post, I'm at work. Let me look at this, but I'm running out of ideas. Is that Norton add on running on both browsers ? Could the be an issue ?

Thanks
Joe :)
  • 0

Advertisements


#32
scottb

scottb

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 193 posts

Hi,

 

Ive been running the laptop a bit today and looking at the processess as I'm using it. The laptop only has 2GB memory preinstalled and as I understand it this is the minimum requirement for running Windows 7(64bit)? I'm starting to wonder if it is'nt just the amount of processess running along with windows and the spikes are when the likes of Nortons or chromes back ground operations kick in? let me know what you think when you get a chance to check ther log.

 

O i almost forgot i've also downloaded Firefox and installed it. Im using this on the laptop as we speak and it seems to be running smother so far.

 

thanks again for all the help

 

Scottb


  • 0

#33
zep516

zep516

    Trusted Helper

  • Malware Removal
  • 8,093 posts
Hello,

2Gigs, part of the concept of 64Bit is it's ability to run and use more Random Access Memory. From what I understand windows 764Bit runs best at 8Gigs. I would consider adding more...

(RAM) is one of the quickest, most efficient and most cost-effective ways to boost performance.

Crucial memory scanner would also helps us determine how much ram is supported by your motherboard and what type to use. See Here.
  • 0

#34
scottb

scottb

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 193 posts

Hi,

 

ok something strange happened there i was just reading your post and the cpu spiked i switched to process explorer and an svchost file was spiking at 80% cpu the pid was 4840. I checked services through task manmager and it was shown under 4840 as defragsvc. I tried to stop the service as it was running but I got an unable to stop service Dialog box. with the message this operation could not be completed. access denied message. but now the service has stopped and i get the same error message if i try to restart it. I'll try and do some research on this but any advice would be appreciated.

 

heres the scan report from crucial it shows 2gb installed but the capacity to hold 8gb. i think ill suggest at least putting another 2gb in it.

 

thanks again scottb

 

Notes about your system:

Although the memory can be installed one module at a time, the best performance comes from using matched pairs of modules.

Your HP - Compaq Presario CQ62 Series (DDR2) system specs as shipped
icon-memory.png
memory
  • Maximum memory: 8192MB
  • Slots:2 (2 banks of 1)
*Not to exceed manufacturer supported memory.
2GB 
Empty
what does this mean?
icon-storage.png
storage
  • Storage: SATA 2 - 3Gb/s
  •  
  •  
    34%
    66% Free (234754142208 Total Storage)
what does this mean?
icon-chipset.png
Chipset
  • Chipset: Intel PM/GM45
what does this mean?
installation guides

  • 0

#35
zep516

zep516

    Trusted Helper

  • Malware Removal
  • 8,093 posts
Hello,

I'll get back to you on those questions,

Service name: defragsvc
Display name: Disk Defragmenter

Description:
Provides Disk Defragmentation Capabilities.

This service is used to defragment disks on a schedule. It will start and stop automatically


Download then run Speccy (free) and post the resultant url for us, details here, this will provide us with information about your computer hardware + any software that you have installed.

Thanks
Joe :)
  • 0

#36
scottb

scottb

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 193 posts

Hi,

 

I trhink i've done that here's the url if it works.

 

http://speccy.pirifo...6mPjR4rXjJQnBe2

 

I also went into system tools to check if the disk defrag was set to run at a set time, but i gvot a message saying disk defrag was scheduled using another program. i do get the option to remove the settings, maybe i should try itb and see what happens?  Ive looked in nortons and i can't find a utility for setting disk defrag just a utility to run in from Nortons. and it was last ran 16 days ago.

 

thanks again

 

scottb


Edited by scottb, 27 October 2015 - 10:50 AM.

  • 0

#37
scottb

scottb

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 193 posts

Hi again,

 

Sorry to keep posting but i've another update, I've found an event in event viewer under windows logs/applications. refering to defrag with id reference 258. I googles this and here is the link https://support.microsoft.com/en-us/kb/2581021 

 

I hope its ok for me to post links if its not just let me know and i'll take it down, basically here's what it tells you will remedy the issue

 

Disable the Logical Disk Monitoring in the SCOM Base OS Management Pack to stop automatic Defrag Analysis.

is this advisable i dont want to cause any further issues. if so how do i do it?

 

I would appreciate your opinion.

 

thanks again

 

scottb


Edited by scottb, 27 October 2015 - 11:58 AM.

  • 0

#38
zep516

zep516

    Trusted Helper

  • Malware Removal
  • 8,093 posts
Hello,

I would leave the defragsvc service alone. It only runs when your computer defragments itself, that's how should be anyway. Is it running at random for you ?

Can you check how defrag is schuduled to run and make adjustments so it does not interfere with your using the laptop ? For instance mine runs at 3AM on Sunday once a month .

see Here

See if you're able to do this
  • 0

#39
scottb

scottb

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 193 posts

Hi joe,

 

yeah the defragsvc is running at random, when i try to access it through system tools i get a message saying disk defrag was scheduled using another program. i do get the option to remove the settings, by clicking remove settings! I'll try what you've suggested and see what happens.

 

thanks again

 

 

scottb


  • 0

#40
scottb

scottb

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 193 posts

Hi joe,

 

Yeah as i thought this didn't work when trying to acess disk defragmenter i get the yellow triange with an exclamation  mark message, disk defragmenter was scheduled using another program, then in smaller writing, disk defragmenter is currently using customized settings created by another program. Before you could modify the schedule, you must remove the customized settings.

then i have the option to remove settings or cancel. I maybe wrong but i dont think just clicking remove settings is going to cure the issue. Today its ran every 3 or 4 hours.

 

thanks again

 

scottb


Edited by scottb, 27 October 2015 - 03:32 PM.

  • 0

Advertisements


#41
zep516

zep516

    Trusted Helper

  • Malware Removal
  • 8,093 posts
disk defragmenter is currently using customized settings created by another program.

Is that Norton Anti Virus doing that ?

Looks like it is Norton,

http://community.nor...another-program
  • 0

#42
scottb

scottb

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 193 posts

Dont think so, when i go into Nortons, there is no option to schedule disk defragmenter and the last optimization is showing as 17 days ago..

I do get the option under performance to run a utility called optimize disk. this looks like a disk defrag utility but it just runs in real time.

I'm running the real time disk defrag in nortons and the spike happened again with the defragsvc, but ive cancelled the disk optimize trhrough nortons and the spiking is continuing with defragsvc.

its stopping now. I'll post a process explorer log but you cant see much appart from the svchost process.

 

Did you look at the microsoft link i posted about defragsvc?

 

 

Process    CPU    Private Bytes    Working Set    PID    Description    Company Name    Verified Signer
svchost.exe    52.21    13,436 K    5,380 K    4040            
System Idle Process    27.54    0 K    24 K    0            
procexp64.exe    7.79    19,460 K    32,764 K    2712    Sysinternals Process Explorer    Sysinternals - www.sysinternals.com    (Verified) Microsoft Corporation
Interrupts    1.97    0 K    0 K    n/a    Hardware Interrupts and DPCs        
dwm.exe    1.85    56,240 K    27,884 K    2856    Desktop Window Manager    Microsoft Corporation    (Verified) Microsoft Windows
nis.exe    1.81    71,408 K    30,904 K    3804            
System    1.62    208 K    2,656 K    4            
firefox.exe    1.00    217,416 K    186,652 K    1668    Firefox    Mozilla Corporation    (Verified) Mozilla Corporation
SynTPEnh.exe    0.95    7,844 K    7,544 K    3640    Synaptics TouchPad Enhancements    Synaptics Incorporated    (Verified) Synaptics Incorporated
csrss.exe    0.72    2,272 K    14,620 K    556            
mbam.exe    0.70    26,372 K    29,160 K    3040            
svchost.exe    0.61    55,820 K    51,260 K    380    Host Process for Windows Services    Microsoft Corporation    (Verified) Microsoft Windows
taskmgr.exe    0.51    2,972 K    9,600 K    4548    Windows Task Manager    Microsoft Corporation    (Verified) Microsoft Windows
explorer.exe    0.18    37,768 K    47,384 K    2952    Windows Explorer    Microsoft Corporation    (Verified) Microsoft Windows
nis.exe    0.16    53,160 K    10,852 K    2136    Norton Internet Security    Symantec Corporation    (Verified) Symantec Corporation
AppleMobileDeviceService.exe    0.09    3,272 K    4,572 K    1588    MobileDeviceService    Apple Inc.    (Verified) Apple Inc.
BTHelpNotifier.exe    0.06    2,928 K    4,048 K    3608    mcci+McciTrayApp    Alcatel-Lucent    (Verified) Alcatel-Lucent USA
chrome.exe    0.03    34,340 K    61,140 K    4120    Google Chrome    Google Inc.    (Verified) Google Inc
svchost.exe    0.03    24,116 K    25,704 K    660    Host Process for Windows Services    Microsoft Corporation    (Verified) Microsoft Windows
svchost.exe    0.03    3,296 K    4,044 K    3136    Host Process for Windows Services    Microsoft Corporation    (Verified) Microsoft Windows
conathst.exe    0.03    1,620 K    5,832 K    3632    Google Chrome (Norton Identity Safe native host)    Symantec Corporation    (Verified) Symantec Corporation
iPodService.exe    0.02    2,152 K    3,844 K    4156    iPodService Module (64-bit)    Apple Inc.    (Verified) Apple Inc.
chrome.exe    0.02    41,964 K    51,464 K    2664    Google Chrome    Google Inc.    (Verified) Google Inc
wmpnetwk.exe    0.01    11,524 K    8,904 K    4964    Windows Media Player Network Sharing Service    Microsoft Corporation    (Verified) Microsoft Windows
taskhost.exe    0.01    12,276 K    11,832 K    2588    Host Process for Windows Tasks    Microsoft Corporation    (Verified) Microsoft Windows
csrss.exe    0.01    1,948 K    2,880 K    496            
svchost.exe    < 0.01    14,940 K    11,460 K    1256    Host Process for Windows Services    Microsoft Corporation    (Verified) Microsoft Windows
HPMSGSVC.exe    < 0.01    2,192 K    5,196 K    3968    HP Message Service    Hewlett-Packard Development Company, L.P.    (A certificate was explicitly revoked by its issuer) Hewlett-Packard Development Company, L.P.
iTunesHelper.exe    < 0.01    4,128 K    6,452 K    3716    iTunesHelper    Apple Inc.    (Verified) Apple Inc.
chrome.exe    < 0.01    48,388 K    40,404 K    5868    Google Chrome    Google Inc.    (Verified) Google Inc
conhost.exe    < 0.01    1,364 K    4,852 K    5992    Console Window Host    Microsoft Corporation    (Verified) Microsoft Windows
HPSA_Service.exe    < 0.01    29,656 K    21,496 K    824    HP Support Assistant Service    Hewlett-Packard Company    (Verified) Hewlett-Packard Company
pcContextHookShim.exe    < 0.01    1,260 K    2,676 K    3836    mcci+McciContextHookShim    Alcatel-Lucent    (Verified) Alcatel-Lucent USA
GWX.exe    < 0.01    3,124 K    716 K    3792    GWX    Microsoft Corporation    (Verified) Microsoft Windows
WmiPrvSE.exe        2,740 K    5,256 K    344            
WmiPrvSE.exe        2,584 K    6,660 K    5904            
WLIDSVCM.EXE        1,000 K    1,464 K    2880            
WLIDSVC.EXE        4,832 K    5,712 K    2648            
winlogon.exe        2,464 K    2,752 K    600            
wininit.exe        1,284 K    1,888 K    568            
TrustedInstaller.exe        4,356 K    3,172 K    4728            
taskeng.exe        1,504 K    4,856 K    5236            
SynTPHelper.exe        896 K    1,560 K    4388            
svchost.exe        3,944 K    5,264 K    884    Host Process for Windows Services    Microsoft Corporation    (Verified) Microsoft Windows
svchost.exe        3,748 K    5,628 K    808    Host Process for Windows Services    Microsoft Corporation    (Verified) Microsoft Windows
svchost.exe        18,840 K    13,940 K    936    Host Process for Windows Services    Microsoft Corporation    (Verified) Microsoft Windows
svchost.exe        7,636 K    9,132 K    424    Host Process for Windows Services    Microsoft Corporation    (Verified) Microsoft Windows
svchost.exe        6,216 K    8,876 K    1888    Host Process for Windows Services    Microsoft Corporation    (Verified) Microsoft Windows
svchost.exe        2,344 K    3,740 K    1916    Host Process for Windows Services    Microsoft Corporation    (Verified) Microsoft Windows
svchost.exe        984 K    1,604 K    2320    Host Process for Windows Services    Microsoft Corporation    (Verified) Microsoft Windows
svchost.exe        10,240 K    9,256 K    1424    Host Process for Windows Services    Microsoft Corporation    (Verified) Microsoft Windows
svchost.exe        3,900 K    4,152 K    2528    Host Process for Windows Services    Microsoft Corporation    (Verified) Microsoft Windows
svchost.exe        996 K    1,592 K    2084    Host Process for Windows Services    Microsoft Corporation    (Verified) Microsoft Windows
svchost.exe        6,760 K    11,056 K    5664            
svchost.exe        2,232 K    4,276 K    1812    Host Process for Windows Services    Microsoft Corporation    (Verified) Microsoft Windows
svchost.exe        2,256 K    2,620 K    3244    Host Process for Windows Services    Microsoft Corporation    (Verified) Microsoft Windows
svchost.exe        4,416 K    7,836 K    1768    Host Process for Windows Services    Microsoft Corporation    (Verified) Microsoft Windows
spoolsv.exe        6,824 K    7,264 K    1384    Spooler SubSystem App    Microsoft Corporation    (Verified) Microsoft Windows
smss.exe        372 K    780 K    320            
SkypeC2CPNRSvc.exe        1,812 K    2,172 K    1716    Phone Number Recognition (PNR) module    Microsoft Corporation    (Verified) Skype Software Sarl
SkypeC2CAutoUpdateSvc.exe        1,356 K    2,096 K    1684    Updates Skype Click to Call    Microsoft Corporation    (Verified) Skype Software Sarl
services.exe        5,312 K    6,516 K    672            
SearchIndexer.exe        34,784 K    16,424 K    4128    Microsoft Windows Search Indexer    Microsoft Corporation    (Verified) Microsoft Windows
SeaPort.EXE        3,680 K    8,704 K    6052            
ScanToPCActivationApp.exe        3,396 K    8,532 K    3664    ScanToPCActivationApp    Hewlett-Packard Development Company, LP    (Verified) Hewlett Packard
RtVOsdService.exe        19,408 K    8,264 K    2456    RtVOsdService    Realtek Semiconductor Corp.    (No signature was present in the subject) Realtek Semiconductor Corp.
RtVOsd.exe        1,956 K    4,020 K    1060            
RichVideo.exe        1,192 K    2,348 K    2360    RichVideo Module        (Verified) CyberLink
procexp.exe        2,168 K    4,036 K    4708    Sysinternals Process Explorer    Sysinternals - www.sysinternals.com    (Verified) Microsoft Corporation
pcCMService.exe        1,620 K    3,600 K    2176    mcci+McciCMService    Alcatel-Lucent    (Verified) Alcatel-Lucent USA
nacl64.exe        1,648 K    4,724 K    548    Google Chrome    Google Inc.    (Verified) Google Inc
nacl64.exe        194,936 K    15,488 K    4760    Google Chrome    Google Inc.    (Verified) Google Inc
mDNSResponder.exe        1,932 K    3,472 K    1652    Bonjour Service    Apple Inc.    (Verified) Apple Inc.
LSSrvc.exe        1,160 K    1,848 K    2028    LightScribe Service    Hewlett-Packard Company    (No signature was present in the subject) Hewlett-Packard Company
lsm.exe        2,292 K    2,616 K    700            
lsass.exe        3,748 K    7,432 K    684    Local Security Authority Process    Microsoft Corporation    (Verified) Microsoft Windows
hpwuschd2.exe        864 K    1,856 K    2376    hpwuSchd Application    Hewlett-Packard    (Verified) Hewlett-Packard Company
HPWMISVC.exe        1,552 K    3,076 K    1996    HP Quick Launch WMI Service    Hewlett-Packard Development Company, L.P.    (A certificate was explicitly revoked by its issuer) Hewlett-Packard Development Company, L.P.
hpqwmiex.exe        1,724 K    4,120 K    3776    HP Software Framework WMI Service    Hewlett-Packard Company    (Verified) Hewlett-Packard Company
GoogleCrashHandler64.exe        1,388 K    68 K    5100            
GoogleCrashHandler.exe        1,440 K    912 K    4732            
cmd.exe        1,968 K    3,392 K    5668    Windows Command Processor    Microsoft Corporation    (Verified) Microsoft Windows
chrome.exe        34,912 K    35,388 K    1948    Google Chrome    Google Inc.    (Verified) Google Inc
chrome.exe        45,024 K    55,096 K    1636    Google Chrome    Google Inc.    (Verified) Google Inc
chrome.exe        24,052 K    21,236 K    4984    Google Chrome    Google Inc.    (Verified) Google Inc
armsvc.exe        1,120 K    1,804 K    1520    Adobe Acrobat Update Service    Adobe Systems Incorporated    (Verified) Adobe Systems
AERTSr64.exe        756 K    1,304 K    1548    Andrea filters APO access service (64-bit)    Andrea Electronics Corporation    (Verified) Andrea Electronics
 


  • 0

#43
zep516

zep516

    Trusted Helper

  • Malware Removal
  • 8,093 posts

Did you look at the microsoft link i posted about defragsvc?


I'm looking at it now,

But I'll do a bit more research , not sure if I want to follow through with those instructions just yet. I also see there are others are having similar issue, so perhaps disabling defragsvc for now is the way to go, I think you tried that, but got an admin error, perhaps in safe mode it would disable.
  • 0

#44
scottb

scottb

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 193 posts

Hi,

 

I'm a little confused by this, the link to the Nortons page makes sense also, but why would it not stop when you stop the disk optimation option?

 

Ive disabled disk defragmenter in services, although when I went in, the service was sert to Manual, but the service was stopped and the only option available was start.

 

 

thanks again

 

scottb.


  • 0

#45
zep516

zep516

    Trusted Helper

  • Malware Removal
  • 8,093 posts
Hello,

Head to Start -> Control Panel -> System and Security -> Administrator Tools -> Task Scheduler

Left hand column: Task Scheduler Library -> Microsoft -> Windows -> Defrag -> Right Click ScheduleDefrag (under Name-Status-Triggers) and select Disable (what I would recommend doing) or “Delete” (not a good idea if you wish to restore this scheduled task later).
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP