windows xp - weird performance problems after security breach

  • Thread starter Sergei Shelukhin
  • Start date
S

Sergei Shelukhin

Hi.
I have a following problem. Due to mishandling my computer running
Windows XP Pro was exposed to Internet without a firewall or antivirus
for about 7 hours yesterday. Checking the logs, I noticed many
portscans and 3 hour long (unsuccessful) brute force dictionary attack
against SQL Server.

I have immediately booted into safe mode, and ran Spybot S&D, AdAware
and ClamWin antivirus scans with all the latest databases - nothing
was found. Later I also tried exhaustive disk check w/checkdisc after
booting to recovery console suspecting I have a HD issue however it
found nothing and problem persisted.

The problem was that after a random amount of time (15mins to 4 hours)
after booting system would run out of some invisible resources that is
needed to do everything (handles?) - program will refuse to write
files, sound won't play and USB sticks won't mount, icons would
randomly disappear or change to generic in taskbar and on desktop,
many programs would not be able to write or read files, and fonts in
many programs (FIrefox, Winamp, VS 2005, putty) would change to some
generic font, background would disappear from XP Shutdown dialog etc
The strangest thing is that it happens at random, say if I save 5
files in VS 2005, 2 will save and 4 will not in no particular order,
same with icons disappearing etc).
Previous uptimes for the system were in the range of weeks or months
so it used to be very stable.

ProcessExplorer shows no strange (either by any counters or by their
mere presence) processes.

According to selective process killing and poking around I am starting
to suspect that ctfmon "CTF Loader" process is to blame. I remember
that it was around long ago so it seems to be ok by itself.

What is this process? What do I do to diagnose or solve this problem?
0_o
 
S

Sergei Shelukhin

Hmm. No, looks like killing ctfmon just makes windows work a littlbe
bit longer, problem persists
 
R

Rock

Sergei Shelukhin said:
Hi.
I have a following problem. Due to mishandling my computer running
Windows XP Pro was exposed to Internet without a firewall or antivirus
for about 7 hours yesterday. Checking the logs, I noticed many
portscans and 3 hour long (unsuccessful) brute force dictionary attack
against SQL Server.

I have immediately booted into safe mode, and ran Spybot S&D, AdAware
and ClamWin antivirus scans with all the latest databases - nothing
was found. Later I also tried exhaustive disk check w/checkdisc after
booting to recovery console suspecting I have a HD issue however it
found nothing and problem persisted.

The problem was that after a random amount of time (15mins to 4 hours)
after booting system would run out of some invisible resources that is
needed to do everything (handles?) - program will refuse to write
files, sound won't play and USB sticks won't mount, icons would
randomly disappear or change to generic in taskbar and on desktop,
many programs would not be able to write or read files, and fonts in
many programs (FIrefox, Winamp, VS 2005, putty) would change to some
generic font, background would disappear from XP Shutdown dialog etc
The strangest thing is that it happens at random, say if I save 5
files in VS 2005, 2 will save and 4 will not in no particular order,
same with icons disappearing etc).
Previous uptimes for the system were in the range of weeks or months
so it used to be very stable.

ProcessExplorer shows no strange (either by any counters or by their
mere presence) processes.

According to selective process killing and poking around I am starting
to suspect that ctfmon "CTF Loader" process is to blame. I remember
that it was around long ago so it seems to be ok by itself.

What is this process? What do I do to diagnose or solve this problem?

Malware Removal
http://www.elephantboycomputers.com/page2.html#Removing_Malware
 
S

Sergei Shelukhin

I tried free versions on about every anti-virus and spyware detectors,
and May 2007 MS Malware removal too, to no avail :(

Is there some generic explanation to resources' error? Like say
disappearing icons, why would windows generally do it?
Or "losing" sounds. What is it running of?
My handles hypothesis is also supported by the fact that with each and
every proccess you kill, the rest runs normally for a little more (10
min boost if you kill explorer.exe and dozens of seconds for things
like ATI control panel :D)

I checked handles and files, levels are normal.
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top