1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Solved processes eating up memory - no log to post

Discussion in 'Malware and Virus Removal Archive' started by Harpo, 2010/08/20.

  1. 2010/08/28
    Harpo

    Harpo Well-Known Member Thread Starter

    Joined:
    2005/08/22
    Messages:
    160
    Likes Received:
    0
    I'm sorry, I don't see how to attach a file to my post, so here's the text:

    Process PID CPU Description Company Name Command Line
    System Idle Process 0 98.46
    Interrupts n/a Hardware Interrupts
    DPCs n/a Deferred Procedure Calls
    System 4
    smss.exe 676 Windows NT Session Manager Microsoft Corporation \SystemRoot\System32\smss.exe
    csrss.exe 732 Client Server Runtime Process Microsoft Corporation C:\WINDOWS\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,3072,512 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestThreads=16
    winlogon.exe 756 Windows NT Logon Application Microsoft Corporation winlogon.exe
    services.exe 800 Services and Controller app Microsoft Corporation C:\WINDOWS\system32\services.exe
    svchost.exe 968 Generic Host Process for Win32 Services Microsoft Corporation C:\WINDOWS\system32\svchost -k DcomLaunch
    wmiprvse.exe 2056 WMI Microsoft Corporation C:\WINDOWS\system32\wbem\wmiprvse.exe
    svchost.exe 1048 Generic Host Process for Win32 Services Microsoft Corporation C:\WINDOWS\system32\svchost -k rpcss
    svchost.exe 1136 Generic Host Process for Win32 Services Microsoft Corporation C:\WINDOWS\System32\svchost.exe -k netsvcs
    wuauclt.exe 536 Windows Update Microsoft Corporation "C:\WINDOWS\system32\wuauclt.exe" /RunStoreAsComServer Local\[470]SUSDS72ee58e6e52a494db69139a0f7c08d8d
    wscntfy.exe 1812 Windows Security Center Notification App Microsoft Corporation C:\WINDOWS\system32\wscntfy.exe
    svchost.exe 1204 Generic Host Process for Win32 Services Microsoft Corporation C:\WINDOWS\System32\svchost.exe -k NetworkService
    vsmon.exe 1376 TrueVector Service Zone Labs, LLC C:\WINDOWS\system32\ZoneLabs\vsmon.exe -service
    spoolsv.exe 1616 Spooler SubSystem App Microsoft Corporation C:\WINDOWS\system32\spoolsv.exe
    jqs.exe 1876 Java(TM) Quick Starter Service Sun Microsystems, Inc. "C:\Program Files\Java\jre6\bin\jqs.exe" -service -config "C:\Program Files\Java\jre6\lib\deploy\jqs\jqs.conf "
    mdm.exe 1924 Machine Debug Manager Microsoft Corporation "C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe "
    NMSSvc.Exe 1952 NMS Module Intel Corporation C:\WINDOWS\System32\NMSSvc.exe
    HPZipm12.exe 1980 PML Driver HP C:\WINDOWS\system32\HPZipm12.exe
    svchost.exe 2016 Generic Host Process for Win32 Services Microsoft Corporation C:\WINDOWS\System32\svchost.exe -k LocalService
    svchost.exe 2032 Generic Host Process for Win32 Services Microsoft Corporation C:\WINDOWS\System32\svchost.exe -k imgsvc
    wdfmgr.exe 176 Windows User Mode Driver Manager Microsoft Corporation C:\WINDOWS\system32\wdfmgr.exe
    alg.exe 1888 Application Layer Gateway Service Microsoft Corporation C:\WINDOWS\System32\alg.exe
    lsass.exe 812 LSA Shell (Export Version) Microsoft Corporation C:\WINDOWS\system32\lsass.exe
    explorer.exe 1080 1.54 Windows Explorer Microsoft Corporation C:\WINDOWS\Explorer.EXE
    WinPatrol.exe 236 WinPatrol System Monitor BillP Studios "C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe" -expressboot
    zlclient.exe 496 ZoneAlarm Client Zone Labs, LLC "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
    jusched.exe 516 Java(TM) Update Scheduler Sun Microsystems, Inc. "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
    procexp.exe 880 Sysinternals Process Explorer Sysinternals - www.sysinternals.com "C:\Documents and Settings\Accounting & Payroll\Desktop\ProcessExplorer\procexp.exe"


    The process had stopped, so I set Process Explorer (it's a lot like System Explorer) to run on boot and rebooted before saving the report.

    I have also been running a paging file defragger called PageDefrag by Mark Russinovich on boot for about the past 5 years. Usually it sails right through its checks, but since we ran the fix, it's been pausing for close to a minute on the first step: pagefile.sys.

    I also noticed when looking at the ProcExp log, that a wuauclt.exe file with an identifier similar to:
    is running...

    And last but not least, on this current reboot, it booted normally. Is there any way that the last reboot had to do something that would have caused the way slow boot? I don't know what to think!
     
  2. 2010/08/28
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Your CPU usage looks perfectly fine.
    System Idle Process (CPU NOT used) is listed at 98.46%

    Finish all steps and let me know how things are.

    Still, more RAM is a must.
     

  3. to hide this advert.

  4. 2010/08/28
    Harpo

    Harpo Well-Known Member Thread Starter

    Joined:
    2005/08/22
    Messages:
    160
    Likes Received:
    0
    OK. Thank you, broni. I will finish up on Monday and let you know. I very much appreciate the time you have spent helping me.
     
  5. 2010/08/28
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    You're very welcome :)

    Let me know....
     
  6. 2010/08/30
    Harpo

    Harpo Well-Known Member Thread Starter

    Joined:
    2005/08/22
    Messages:
    160
    Likes Received:
    0
    I'm happy to report that all seems well. I ran one last ESET scan this morning just to ease my own mind, and it came up clean.

    Thanks again for all your help, broni!
     
  7. 2010/08/30
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    You're very welcome :)
    Good luck and stay safe :)
     

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.