Join 100,000 Subscribers:

 

Welcome to the How-To Geek Forums

We encourage you to register on our forums and post any questions you might have. The How-To Geeks monitor this forum and will respond to your question quickly.

How-To Geek Forums » Windows Vista

Tried to solve a problem using advice from here and opened a can of worms!

(14 posts)
  • Started 9 months ago by treymorrison
  • Latest reply from BobJam
  • Topic Viewed 2131 times

treymorrison
Posts: 6

I was searching how to restore my Volume icon in my taskbar and came across this article.

http://www.howtogeek.com/howto.....ows-vista/

I followed the instruction: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explore
only to discover that the "Explore" option was not there. I scrolled down to the comments and came across this statement.

<Dobay Raymund

In case of grayed out or missing system icons it is mostly enough to open the Task Manager, end the explorer process and run it again
(new task, run, explorer). All four system icons will reappear!
Pls check it!>

Followed by the site's endorsement

<The Geek

That's a good point, I updated the article to mention this is for when rebooting doesn't fix the problem.>

After following the instructions given, I ran explorer and the sound icon reappeared. But, then my CPU usage shot to 100% and my Resident Shield Alert shot up a Multiple Threat detection of the same C:\Windows|System32\b4fm.dll Adware Generic4.BWU over and over.

Unfortunately and Obviously, I do not know very much about computers. I rebooted my computer into safe mode and ran AVG and SpyBot S&D but both came up clean. When I went back to regular mode the CPU shot right back up to 100% and I cannot open any files nor do I know if I should remove the infections for AVG says it could be Fatal and lead to a crash. While running Task Manager, different things will rise for the usage, but nothing constant, from TeaTimer.exe to GrooveMonitor.exe.

What should I do? As well, sorry if this is addressed somewhere else in this forum.

I read some info on this at http://www.bleepingcomputer.co.....36182.html
but the conclusion seems vague/i'm pretty much screwed if I have a backdoor trojan. As well, it states that i need superantiapyware. Will I be able to intall new programs and run them from SafeMode, with my computer running at 100% I cannot do anything really in normal mode

Posted 9 months ago #
Top
 
treymorrison
Posts: 6

After some more review, I came across info stating that system32\b4fm.dll is a burn4free file, which I do have on my computer. I currently am running AVG right now and nothing has come up negative despite that the shield alert is right next to it with an increasing number of warnings about this file. How or what should I do to stop my computer from running at 100%?

Posted 9 months ago #
Top
 
BobJam
BobJam
Posts: 889

Hey treymorrison,

Looks like burn4free may contain some adware or PUA ("Potentially Unwanted Applications"). You might try removing burn4free with Revouninstaller, and see if that doesn't reduce your CPU cycles. Is there a burn4free process running at startup or do you have the burn4free app starting when Windows starts?

Take a look here and here.

Posted 9 months ago #
Top
 
k9
k9
Posts: 123

Hi treymorrison,
Could you open msconfig and let us know what all programs are scheduled to run on your system once you logon. It would be better if you could post the log generated by HiJackThis here as it would give us a lot more insight about the processes running on your system. Google for HiJackThis to download the software.

Posted 9 months ago #
Top
 
Odeho19
Odeho19
Posts: 309

@ treymorrison, the link you want for HJT (HiJackThis) is here. Run the log, and post it here, or go to Bleeping Computer, and start a free account with them, and post your log there.

Posted 9 months ago #
Top
 
treymorrison
Posts: 6

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 4:42:34 AM, on 4/21/2009
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18226)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\HP\QuickPlay\QPService.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
C:\Program Files\AVG\AVG8\avgtray.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\PowerISO\PWRISOVM.EXE
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\dvd43\DVD43_Tray.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Users\Trey\Program Files\DNA\btdna.exe
C:\Program Files\MozyHome\mozystat.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Program Files\Hewlett-Packard\HP wireless Assistant\WiFiMsg.EXE
C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe
C:\Windows\system32\Taskmgr.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files\AVG\AVG8\avgscanx.exe
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/.....38;pf=cnnb
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/.....38;pf=cnnb
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/.....38;pf=cnnb
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/.....38;pf=cnnb
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: Microsoft Live Search Toolbar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - c:\Program Files\MSN\Toolbar\3.0.0541.0\msneshellx.dll
O3 - Toolbar: Microsoft Live Search Toolbar - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - c:\Program Files\MSN\Toolbar\3.0.0541.0\msneshellx.dll
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe"
O4 - HKLM\..\Run: [UpdateLBPShortCut] "C:\Program Files\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\LabelPrint" UpdateWithCreateOnce "Software\CyberLink\LabelPrint\2.5"
O4 - HKLM\..\Run: [UpdatePSTShortCut] "C:\Program Files\CyberLink\DVD Suite\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\DVD Suite" UpdateWithCreateOnce "Software\CyberLink\PowerStarter"
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [QlbCtrl.exe] C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [UpdateP2GoShortCut] "C:\Program Files\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\Power2Go" UpdateWithCreateOnce "SOFTWARE\CyberLink\Power2Go\6.0"
O4 - HKLM\..\Run: [UpdatePDIRShortCut] "C:\Program Files\CyberLink\PowerDirector\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\PowerDirector" UpdateWithCreateOnce "SOFTWARE\CyberLink\PowerDirector\7.0"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [HP Health Check Scheduler] c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [DNS7reminder] "C:\Program Files\Nuance\NaturallySpeaking10\Ereg\Ereg.exe" -r "C:\ProgramData\Nuance\NaturallySpeaking10\Ereg.ini
O4 - HKLM\..\Run: [dvd43] C:\Program Files\dvd43\dvd43_tray.exe
O4 - HKCU\..\Run: [HPAdvisor] C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe autorun=AUTORUN
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [EPSON NX100 Series] C:\Windows\system32\spool\DRIVERS\W32X86\3\E_FATIEDA.EXE /FU "C:\Windows\TEMP\E_S8727.tmp" /EF "HKCU"
O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Users\Trey\Program Files\DNA\btdna.exe"
O4 - HKCU\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKCU\..\Run: [Nero PhotoShow Media Manager] C:\PROGRA~1\Nero\PHOTOS~1\data\Xtras\mssysmgr.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Global Startup: MozyHome Status.lnk = C:\Program Files\MozyHome\mozystat.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~1.0_0\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~1.0_0\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O13 - Gopher Prefix:
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: avgrsstx.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Com4QLBEx - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe
O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files\HP Games\My HP Game Console\GameConsoleService.exe
O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: MozyHome Backup Service (mozybackup) - Mozy, Inc. - C:\Program Files\MozyHome\mozybackup.exe
O23 - Service: Norton Internet Security - Unknown owner - C:\Program Files\Norton Internet Security\Engine\16.0.0.125\ccSvcHst.exe (file missing)
O23 - Service: Recovery Service for Windows - Unknown owner - C:\Program Files\SMINST\BLService.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared files\RichVideo.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

--
End of file - 10795 bytes

Posted 9 months ago #
Top
 
treymorrison
Posts: 6

Thanks in advance everyone...sorry it took so long to reply...computer is slow but I appreciate everything

Posted 9 months ago #
Top
 
drifta
drifta
Posts: 439

it seems that a program called DNA is playing with your system.
what is the programs full name? and what are you using it for?
it is located here C:\Users\Trey\Program Files\DNA\btdna.exe

if you have no use of it..use revouninstaller and get rid off it
http://www.revouninstaller.com.....nload.html

EDIT: it seems the btdna.exe is a process of bittorrent.
this site states that it can cause excessive system resources usage and thereofre you should remove it.
http://www.pcpitstop.com/libra.....a.exe.html

Posted 9 months ago #
Top
 
treymorrison
Posts: 6

Ran the Optimizer option at pcpitstop, here are the results

C:\Users\Trey\AppData\Local\Temp5 files, 0.39 MB
Recycle Bin C6 files, 8873.67 MB
Recycle Bin D0 files, 0.00 MB
IE cache751 files, 12.33 MB
IE cache1520 files, 18.51 MB
Internet performanceScanned 14 items
Firefox performanceScanned 16 items
Ping33 milliseconds avg
CLSIDsScanned 7087 items
ProgidsScanned 6439 items
AppPathsScanned 63 items
TypelibsScanned 744 items
InterfacesScanned 13159 items
MUICachesScanned 0 items
AddRemovesScanned 208 items
ARPCachesScanned 0 items
FileExtsScanned 144 items
MenuOrdersScanned 0 items
System performanceScanned 8 items
Startup programsScanned 35 items
Download speed267KB, 3.56 sec; 600 kbps
Download speed1281KB, 14.80 sec; 692 kbps

Junk files come from several sources. The Recycle Bin holds deleted files so you can retrieve them if you later decide that you should not have deleted them. However, files in the Recycle Bin can use a lot of space; empty your Recycle Bin to reclaim this space. Windows and applications create temporary files while they are running. In some cases though, applications do not clean up after themselves. Other examples include the caches for Internet Explorer and Firefox. Although caches help a dial-up connection, oversized caches can hurt performance on a broadband connection.
Junk Files
• Temporary Files (5 files, 0.39 MB)
o C:\Users\Trey\AppData\Local\Temp
• Recycle Bins (6 files, 8873.67 MB)
o C:\$Recycle.Bin
o D:\$Recycle.Bin
• Internet Caches (2271 files, 30.84 MB)
o C:\Users\Trey\AppData\Local\Microsoft\Windows\Temporary Internet Files\CONTENT.IE5
o C:\Users\Trey\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\CONTENT.IE5

Optimizing your Internet settings can help to dramatically boost your Internet speed. Internet-related settings can be tuned for faster throughput and may provide up to a 200% increase in Internet performance. Optimize determines the best settings by performing a dynamic test under the actual conditions currently being experienced on your connection.
Internet Settings
• HTTP (4 changes recommended)
o ProxyHttp1.1=1
o SyncMode5=4
o MaxConnectionsPerServer=6
o MaxConnectionsPer1_0Server=6
• TCP/IP (7 changes recommended)
o MTU=1500
o DefaultTTL=64
o EnablePMTUDiscovery=1
o EnablePMTUBHDetect=1
o TcpMaxDupAcks=2
o Tcp1323Opts=1
o SackOpts=1
• Firefox (14 changes recommended)
o ui.submenuDelay=50
o content.interrupt.parsing=true
o content.max.tokenizing.time=3000000
o content.maxtextrun=8191
o content.notify.backoffcount=5
o content.notify.interval=750000
o content.notify.ontimer=true
o content.switch.threshold=750000
o nglayout.initialpaint.delay=500
o network.http.max-connections=32
o network.http.max-connections-per-server=6
o network.http.max-persistent-connections-per-server=4
o network.http.pipelining=true
o network.http.pipelining.maxrequests=8

Below is a list of unnecessary programs that run every time that this computer is started. If there are programs listed, then removing them from automatic startup may improve the performance of your computer and reduce memory usage. We suggest that you remove them, but you can continue to run any of them by unchecking the box next to the entry below. To find out more about an item, click on it.
Startup Programs
o BitTorrent DNA
o InstallShield Update Service
o Intel Graphics
o Intel Hotkeys
o Intel(R) Common User Interface
o Adobe Acrobat SpeedLauncher
o Sun Java Update
o HP software update
o Groove Monitor
o QuickTime Icon

Programs sometimes leave incorrect information behind in the registry, either because they uninstall incorrectly or because the files associated with the entries have been moved or deleted. Cleaning the Windows registry will help to keep your PC in working order and keep the system running at peak performance.
Registry Fixes
• CLSIDs (13 fixes)
• Progids (90 fixes)
• AppPaths (2 fixes)
• Typelibs (2 fixes)
• Interfaces (14 fixes)
o FileExts (112 fixes

Installed revouninstaller & deleted DNA as suggested. Rebooting computer, however Shield is still telling me threat detection C:\Windows|System32\b4fm.dll Adware Generic4.BWU.

got to go to class, thank you so far

Posted 9 months ago #
Top
 
drifta
drifta
Posts: 439

im not sure what is the cause of the warning messages.
1stly i would use malwarebytes anti-malware and do a full scan of your machine http://download.cnet.com/Malwa.....tag=button (its jsut a trial but it should be sufficient) if maklware bytes detects anything i would get rid of those detections

then i would suggest you get your machine scanned online for viruses http://www.eset.com/onlinescan/

Posted 9 months ago #
Top
 
BobJam
BobJam
Posts: 889

Don't know if this is related to your problem, but from your HJT log I count some 35+ programs loading at startup. NO WONDER YOUR MACHINE IS SLOW with all that stuff running in the background. Your systray must take up the entire task bar!

You need to pare that list down to a much more manageable number . . . like maybe 5 or so.

Go to this page and download "Startup Inspector" and run it. Then you will be able to determine precisely what startup items you actually need booting along with Windows and you can disable the others. ("Disable" is not the same as "delete" . . . you won't be deleting any of these programs, you'll just be removing them from the startup group. If you find that you really do need something to start when Windows starts, you can always re-enable it.)

As I said, this may not be the solution to your problem, but it sure will improve that "slow" behavior.

As far as the alert goes, I think maybe it's a false positive or the alert just indicates a PUA because burn4free does contain some adware. You can just remove that program . . . there are plenty of other free burning programs that DON'T contain adware. Once you remove that program the alert should go away.

Posted 9 months ago #
Top
 
treymorrison
Posts: 6

I installed the anti-malware software recommended and my computer came up clean. I stopped all the unnecessary start up programs as well. My computer is still running at 100%. The following comment bellow is from Gadzooks64 from the same thread that my problem originated and he seems to have had the same problem I did but I do not know how he fixed it. I have not been able to find a way to e-mail other people on this site and I was hoping that someone could help me either contact him or have an idea of what he did.
Thanks in advance

Gadzooks64

I did this and it messed up my machine but good. I didn't even have Explorer folder under Policies. I had to go back and delete those registry entries to get my CPU to stop being pegged at 100%.

I found that the process described here has worked for me:

http://www.howtogeek.com/howto.....ows-vista/

Posted 9 months ago #
Top
 
cmitchrunner
Posts: 1

treymorrison I know it has been a long time since you posted but I noticed that you were using Spybot S&D. You also mentioned TeaTimer.exe as a culprit for hogging megs while processing. I did some research and discovered that of late Spybot as got bad reveiws. They used to be outstanding a couple years back but now come up wanting. My PC was fine before I installed Spybot and afterwards I had issues of running at 100% and TeaTimer.exe(Spybot application) hogging space. I know it's not a very "geek" aproach but I uninstalled Spybot and my toubles went away 5 minutes later after reboot. I hope this helps others who may have the same issue.

Posted 5 months ago #
Top
 
BobJam
BobJam
Posts: 889

I think the Geek, or MysticGeek, or both is/are Spybot fans and TeaTimer advocates. But I tend to agree with cmitchrunner . . . Spybot and TeaTimer are likely suspects.

Posted 5 months ago #
Top
 

RSS feed for this topic

Reply

You must log in to post.

Our Friends
Getting Started
About How-To Geek
What Is That Process?
svchost.exe
jusched.exe
dwm.exe
ctfmon.exe
wmpnetwk.exe
mDNSResponder.exe
wmpnscfg.exe
rundll32.exe
wfcrun32.exe
Ipoint.exe
Itype.exe
Wfica32.exe
Mobsync.exe
conhost.exe
Dpupdchk.exe Adobe_Updater.exe

Copyright © 2006-2010 HowToGeek.com. All Rights Reserved.