Home » Questions » Computers [ Ask a new question ]

some strange services in task manager and in msconfig/startup that I cannot close

some strange services in task manager and in msconfig/startup that I cannot close

"I was trying to fix a friend's computer because it was really slow, it was working but after some 20 minutes it was starting go really slow or just freeze
and I've formatted the hard drive, installed windows xp, and after a while I've noticed that it is still slow, so this is what I saw in:
Task Manager / processes"

Asked by: Guest | Views: 254
Total answers/comments: 3
Guest [Entry]

"I believe these are program-generated task names and that your computer is still infected. This means that some product that you install is actually a virus, or that another computer in your network is re-infecting yours every time. Better also check that the computer is really behind a firewall.

I suggest that you :

Reformat and reinstall Windows
Install several antivirus products, at least Malwarebytes' Anti-Malware and Avast and an anti-intrusion product such as Threatfire.
Then install one-by-one any product, analyzing first all installations. Re-download the installation files from their sites and make sure that these sites are not known malware. Do not trust your friend. See this article:
Check A Website For Malware With Google Safe Browsing Tool"
Guest [Entry]

"Harrymc's solution is good, sometimes when a virus infestation is very big, you just don't know if you can trust the system again. Like you are seeing, there could be a number of things that retrigger the malware to come back at a later date.

However, some general advise for fixing a malware infected system:

Start with a good tool such as Spybot Search and Destroy or Malwarebytes Anti Malware and perform a full scan.

After this has finished, use Microsoft / Sysinternals Autoruns and look through most of the tabs (you especially want to pay close attention to Logon and Scheduled tasks) and delete most of the items that you think are viruses or research them first.

Next, protect your system with a good antivirus. I personally recommend Microsoft Security Essentials.

Again though, once you have a virus on your system, you have no idea what it can do or where it can hide, it is possible to hide from AV scans and sometimes it is both safer and quicker to reinstall. The decision is up to you!"
Guest [Entry]

"If the re-infection don't come back from the network or the launching of an old executable, it's certainly a boot sector virus.
You could manually look for it but it's more secure to follow SLaks's answer...

So, the more secure (maybe paranoïd) way:

Apply the answer from SLaks. But I recommend to use the latest kaspersky removal tool and malwarebytes from the boot cd, with all options to speed the scan disabled. (You could easily include them in ubcd4win, like spybot and many other tools...) and delete everything they found.
Backup your files
Apply the answer from harrymc but according Will and the latest av-comparative test, Microsoft Security Essentials is the (actual) better (free) anti-malware. (Personally I use: Kaspsersky Anti-Virus + Comodo Internet Security and Sandboxie to test new software / browse securely)

Note: if the usb autorun of your computer was activated, you should check your computer too..."