Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

Not sure if I have malware!


  • Please log in to reply

#76
rogerbid

rogerbid

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 226 posts
Update: Sorry Ron, the internet has been down here preventing me from doing the tasks you requested. I will hopefully be able to write tomorrow, sending this from my cell phone! Roger
  • 0

Advertisements


#77
rogerbid

rogerbid

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 226 posts

Hi Ron,

 

Sorry for the delay in replying, my internet connection was down for a lot of yesterday.

 

I have now managed to follow your last instructions and attach the following .txt files:

 

  1. procexp64.exe > Edge Closed > VPN enabled > Battery disconnected > AC Power connected
  2. procexp64 2.exe > Edge Closed > >VPN Disabled > Battery disconnected > AC Power connected
  3. Hardware Interrupts and DPCs > Edge Closed > VPN Disabled > Battery connected > AC Power disconnected
  4. Hardware Interrupts and DPCs 2 > Edge Closed > VPN enabled > Battery connected > AC Power disconnected
  5. Hardware Interrupts and DPCs 3 > Edge Closed > VPN enabled > Battery connected > AC Power connected
  6. Hardware Interrupts and DPCs 4 > Edge Closed > VPN Disabled > Battery connected > AC Power connected

At this point I installed Firefox (I did not get a check box offering ‘Import from Edge’ but checked ‘Content Process Limit to 1’ as instruct.)

 

      7. Hardware Interrupts and DPCs 5 > Edge Closed >Firefox running > VPN enabled > Battery and AC Power connected

      8. Hardware Interrupts and DPCs 6 > Edge Closed >Firefox running > VPN disabled > Battery and AC Power connected

 

I have looked at the .txt files and it appears the interrupts numbers shown there are consistently higher than those showing in the Process Explorer screen.  I am not sure if I can attach a video to a post in this forum and will check that using my desktop PC shortly.  For now however I will view a video taken on my phone and transcribe here the changing interrupts in succession when the last 2 files above were created. (I hope this makes sense!  If I am successful in attaching the videos it will be clearer)

 

When file Hardware Interrupts and DPCs 5.txt was created figures displayed per second were:

 

      1.14/1.11/1.10/1.10/1.14/1.16/1.24/1.21/1.17/1.17/1.44  (Figure in txt file is 2.37!)

 

When file Hardware Interrupts and DPCs 6.txt was created figures displayed per second were:

 

      2.72/2.59/2.66/3.09/3.06/2.71/2.65/2.96 (Figure in txt file is 3.58!)

 

I have noticed similar discrepancies before, I should have said something, sorry.  I don’t know if any of the above helps at all, I am now totally confused.

 

I do believe however that the laptop is very much better for all your efforts and I thank you again!  Incidentally, since the slow boot yesterday I have timed the start ups today and it is very much better again, must have been a temporary thing!

 

Roger

Attached Files


Edited by rogerbid, Yesterday, 01:26 AM.

  • 0

#78
rogerbid

rogerbid

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 226 posts

Hello Ron

 

As I suspected I am not able to attach video files, I reduced them to .flv format in case that helped but no luck.  If there is a way to share these files please advise, :)

 

I will look forward to hearing more in due course, thanks,

 

Roger


  • 0

#79
RKinner

RKinner

    Malware Expert

  • Expert
  • 22,748 posts
  • MVP

ETDCtrl.exe seems to be present when Interrupts at highest.

Right click on the clock and select Task Manager

Then click on Startup tab. 

 

Find ETDCtrl

in the first column and select it.  Then Disable.  Reboot.

This is part of the touchpad but I think it only provides the fancy stuff so you probably won't notice any difference.

 

What does Interrupts say now?

 

Video files would need to be 2 MB or less and would have to be zipped up to attach as the forum limits the types of files and the size you can post.  You have to use a third party online file storage and send me the link.  Something like one of these:

https://www.creative...e-tools-3132117


  • 0

#80
rogerbid

rogerbid

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 226 posts

Hello Ron,

 

I am attaching a new .txt file created with VPN Off, battery installed and AC power connected.  Edge running.

 

I will try to send a link to the videos shortly in the hoped that they show something useful,

 

Best wishes,

 

Roger

Attached Files


  • 0

#81
rogerbid

rogerbid

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 226 posts

Here is a link to the 2 flv files, I hope you can get them OK.  Firefox says the link will expire after one download so i will send again to give 2 opportunities to  view

 

https://send.firefox...CIfOgsAwlMkHrrA

 

Roger


  • 0

#82
rogerbid

rogerbid

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 226 posts

2nd link as promised

 

https://send.firefox...ExTVVyzUUtce8Xg


  • 0

#83
RKinner

RKinner

    Malware Expert

  • Expert
  • 22,748 posts
  • MVP

I think you have another Microsoft Update going on in the Process Explorer log.  I got a new one today too.

 

What is going on in the videos?  Interrupts finally settles to a good value.


  • 0

#84
rogerbid

rogerbid

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 226 posts

I think you have another Microsoft Update going on in the Process Explorer log.  I got a new one today too.  I have checked Windows Updates and no activity is obvious, but the Security and Maintenance page shows it was active this morning.  I am attaching two screen grabs in case they help

 

What is going on in the videos?  Interrupts finally settles to a good value.  I thought it worth trying to capture the screen on my phone, do you think we have done all we can now?  I do believe the laptop is running very much better than before, :)

 

I look forward to hearing from you when you have a moment, thanks,

 

Roger

 

Attached Thumbnails

  • Maintenance 28th May.JPG
  • Update screenshot.jpg

  • 0

#85
RKinner

RKinner

    Malware Expert

  • Expert
  • 22,748 posts
  • MVP

OK.  It looks in the videos like it is doing OK.  I guess the button you select is to turn off the VPN.  We can always stop if you are happy with it.


  • 0

Advertisements


#86
rogerbid

rogerbid

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 226 posts

Hello Ron,

 

Thank you for your latest reply.  I am reluctant to ask you to give yet more of your time to resolving issues when I can see that you have already helped me to make very significant improvements to the system.  I have no doubt that my wife will notice these improvements immediately she starts to use the laptop.

 

However if you still think there are issues that can be eliminated, and more importantly are happy to continue despite the delays caused by our time differences, I am also happy to continue.  I leave the decision up to you and assure you that I am most grateful for your patience and expertise in achieving the current level of performance.

 

You may recall we mentioned early on that I have my own laptop that could do with some debugging but suggest we defer any investigation for a few days to give you a break!  Let me know how you feel about continuing with one or other device and we will go from there.

 

Thank you once again for your perseverance and I send you my very best wishes,

 

Roger

 

 

 

 


  • 0

#87
RKinner

RKinner

    Malware Expert

  • Expert
  • 22,748 posts
  • MVP

We can start on the next one any time.  Forum is super slow right now and you are my only client.  Give me the FRST logs, process explorer log and speccy log:

 

  • Get FRST from http://www.bleepingc...very-scan-tool/You need to download the appropriate tool for your PC.  If you don't know if you have a 32 or 64 bit system get them both.  Only one will work and that's the right one.
  • Right click to run as administrator (XP users click run after receipt of Windows Security Warning - Open File). When the tool opens click Yes to disclaimer.
  • Check the Addition.txt box
  • Press Scan button.
  • It will produce a log called FRST.txt in the same directory the tool is run from.  
  • Please copy and paste log back here.
  • It will generate another log (Addition.txt - also located in the same directory as FRST.exe/FRST64.exe). Please also paste that along with the FRST.txt into your reply.


Smart Screen, Windows Defender and Avast have all been blocking FRST recently.  It's a false positive so pause your antivirus when downloading or running FRST.  If you get a message saying Smart Screen has blocked it you can click on More Info and you will see an option to Run Anyway.

 

Get Process Explorer

https://live.sysinte...com/procexp.exe

Save it to your desktop then run it (Vista or Win7+ - right click and Run As Administrator).  

View, Select Column, check Verified Signer, OK
Options, Verify Image Signatures


Click twice on the CPU column header  to sort things by CPU usage with the big hitters at the top.  

Wait a full minute then:

File, Save As, Save.  Note the file name.   Open the file  on your desktop and copy and paste the text to a reply.


Copy the next 2 lines:

TASKLIST /SVC  > \junk.txt
notepad \junk.txt

Open an Elevated Command Prompt:
Win 7: Start, All Programs, Accessories then right click on Command Prompt and Run as Administrator
Win 8: http://www.eightforu...indows-8-a.html
win 10: http://www.howtogeek...-in-windows-10/

Right click and Paste (or Edit then Paste) and the copied lines should appear.
Hit Enter if notepad does not open.  Copy and paste the text from notepad into a reply.


Get the free version of Speccy:

http://www.filehippo...ownload_speccy/ 

(Look in the upper right for the Download
Latest Version button  - Do NOT press the large Start Download button on the upper left!)  
Download, Save and Install it.  Tell it you do not need CCLEANER.    Run Speccy.  When it finishes (the little icon in the bottom left will stop moving),
File, Save as Text File,  (to your desktop) note the name it gives. OK.  Open the file in notepad and delete the line that gives the serial number of your Operating System.  
(It will be near the top,  10-20  lines down.) Save the file.  Attach the file to your next post.  Attaching the log is the best option as it is too big for the forum.  Attaching is a multi step process.

First click on More Reply Options
Then scroll down to where you see
Choose File and click on it.  Point it at the file and hit Open.
Now click on Attach this file.





 


  • 0






Similar Topics

6 user(s) are reading this topic

0 members, 6 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP