PC problem - maybe MSMPENG.EXE

Kestrel

Junior Member
Jul 12, 2012
4
0
0
I have XP Home running and I'm able to access the internet through Firefox (Haven't tried another browser)

I noticed that I was not able to open one of my programs last week - Libronix. I got the splash screen, then no activity. I checked Task Manager and found that the only Cpu Cycles were being used by System Idle Process (99%) and occasionally Task Manager would use a few.

At that point, I realized that I let windows update at about the time that this all started.

While I was talking with tech support for Libronix, I realized that I could not open Windows Explorer. The window for Explorer would open, but It had a flashlight icon searching for my drives and my documents. It could not find any drives or documents for 30 minutes, and when I tried to close Explorer, I got an hourglass icon and nothing was responsive. I did a hard shutdown.

Things started normally, and I tried to run windows Restore, a hard drive monitor (speedfan), Add/Remove hardware, and Microsoft Essentials. Each time, the machine locked up as described above, and each time I had to do a hard shutdown.

I plugged in my backup HDD, but I have to use Windows Explorer to start it, and Explorer just ran the flashlight icon.

Today, I hit F2 and ran setup at startup. There is a hard drive diagnostics tool there, and it reports the hard drive is OK.

Today I tried to install Norton Ghost, but it hung at the dialog box that says "preparing to install" for 30 min. When I clicked cancel it became unresponsive, so I did another hard shutdown.

I AM able to run WinPatrol Plus, and the only change listed at the time of the problem is MSMPENG.EXE on July 7. If I remember correctly, this file was a resource hog and gave me trouble before and I thought I got rid of it. The Windows update probably reinstalled it. I know it turned real-time monitoring on, and I shut it off yesterday in MS Windows Essentials.

I tried to kill MSMPENG.EXE in WinPatrol Plus, but no joy.

I plan to keep the computer on and connected to the internet until I know more about what is going on, in hopes that I can salvage files that are not backed up. I'm encouraged a bit by what I have done today. Last night, I thought the HDD was dying.

Anyone have any ideas about this situation? Any help would be greatly appreciated! Thanks in advance for your advice!
 
Last edited:

Bubbaleone

Golden Member
Nov 20, 2011
1,803
4
76
The MsMpEng.exe application is part of Microsft Security Essentials. If MSE is currently installed and you also have any other AV product installed, then a conflict is likely the cause for the extreme resource usage and resulting unresponsiveness.

See this List of anti-malware product removal tools. Even if you've previously uninstalled any other AV products you've tried out, there may still be remnants of those old AV programs that are causing the conflict. So think of any previous AV software you used, then use the appropriate anti-malware product removal tool to make sure it's really removed from your system.

There's plenty more to do after this if the problem continues, but do this first then post back with your result.
 

Kestrel

Junior Member
Jul 12, 2012
4
0
0
Thanks, Bubbaleone -

I have used AVG and Avira - I uninstalled both, but I didn't purge either with the additional programs you list. I'll give both a try and report back. Thanks!

EDIT - Wait a minute - they both probably require me to restart after running. Is there any way to know if the HDD is likely to fail on restart? I'd like to keep as many of my files as possible, but right now, I don't have access to them to make a backup.

I am thinking of running them, but not choosing to restart. I have Acronis True Image 2012. After running the other programs, I could try to install that. If it hangs, I would have to have a hard shutdown. If Acronis does install, I could clone to a new HDD. - END EDIT
 
Last edited:

sm625

Diamond Member
May 6, 2011
8,172
137
106
It sounds like a bad hdd, or at best a bad sector on an hdd. If your hdd is trashed it may be too late to try and clone to a new one. You should either install the HDD on a different system and run a tool like chkdsk, or use a linux disc to run some hdd diagnostic utility.
 

Kestrel

Junior Member
Jul 12, 2012
4
0
0
I ran the removal programs, but I had to go into safe mode to do it. When I was in safe mode, I ran a full scan of malwarebytes. It found a virus called Trojan.FakeAlert I removed it, but the programs are still unresponsive. I'm going back into safe mode and will run it again. Thanks to all. I'll keep trying to remove any virus.
 

Bubbaleone

Golden Member
Nov 20, 2011
1,803
4
76
Malwarebytes is a great program that I regularly use myself, but it won't handle really tough infections the way ComboFix can. When you state it's still unresponsive suggests you probably have multiple infections.

Go to this bleepingcomputer.com webpage: How to use ComboFix; there's a ComboFix download link on the page. Before you download and run ComboFix, carefully read the instructions so you know what to expect and how to use it, and you should follow the advice about getting help from one of their removal specialist; it's free.

If you decide to run ComboFix on your own, when the virus/malware scan begins, don't touch your mouse or keyboard until the ComboFix log file opens in Notepad on your desktop.

.
 
Last edited:

Kestrel

Junior Member
Jul 12, 2012
4
0
0
I have been tied up with other things, but I did run Malwarebytes twice more.

The second time it found the same malware in a different location and I killed it. The third time through, it found no threats.

I am able to access my documents now.

I also talked to a friend who is a software pro and he said that it can't hurt to run Kasperskys rootkit scan. I tried it and it came up with nothing.

While in safe mode, I was able to run S.M.A.R.T. and everything looks good. Also, in safe mode I can see the drives and access them.

At this point I am forced to suspend work on this because I have to be out of town for a while.

Since I can see my documents now, Once I get back I'll work on backing everything up before I try to clean any more. Thanks for the help, everyone!

Saga to resume when I get back.